|
|
CHAPTER V. International cooperation
themselves to be regarded as the legal basis for cooperation and for specified unlawful
conduct to be treated as qualifying offences for mutual legal assistance and extradition
purposes within the national laws of States parties.
334. Many countries, including China, rely upon the principle of reciprocity as the
basis for providing international cooperation. Under Chinese law, law enforcement agen-
cies and judicial authorities can conduct international cooperation, including mutual
assistance or judicial cooperation
(including extradition), on a treaty basis. In the
absence of a treaty, reciprocity can also be a legal basis for mutual assistance and
extradition cooperation. At the expert group meeting, the expert from China highlighted
one example of successful cooperation between authorities in China and the United
States that resulted in the closure of the world’s largest Chinese-language pornography
website, which was hosted in the United States and aimed at Internet users in China
and other Asian countries.
335. Several participants at the expert group meeting referred to issues related to the
sensitive nature of much information (often intelligence-based) associated with terrorism
investigations and the inherent challenges, not only in the international cooperation
context but also nationally, facing agencies wishing to share such information with
counterparts. Several experts highlighted that information was often highly sensitive in
nature and that sharing it became difficult in the absence of a formal information-
sharing mechanism containing appropriate conditions regarding its use and
disclosure.
336. This issue is considered in more detail in the next chapter, relating to prosecu-
tions, in the context of evidential issues associated with translating intelligence material
into admissible evidence and the disclosure of evidence in criminal proceedings.
99
VI. ProsecutionsVI.
A. Introduction
337. An integral part of the universal legal framework against terrorism, and of the
United Nations Global Counter-Terrorism Strategy, is the obligation imposed on States
to deny safe haven and bring to justice perpetrators of terrorist acts, wherever such
acts might occur. In order to achieve the last of these objectives, countries not only
require effective counter-terrorism legislation, criminalizing terrorist acts and facilitating
necessary international cooperation, but also the capacity to apply specialized investiga-
tive techniques and prosecution strategies to ensure the collection, preservation, produc-
tion and admissibility of evidence (often intelligence-based) when prosecuting suspected
terrorists, while ensuring international standards of treatment for accused persons.
338. The role of prosecutors in the prosecution of terrorism cases has become
increasingly complex and demanding. In addition to responsibility for the conduct of
criminal proceedings, prosecutors are becoming more involved in the investigative and
intelligence-gathering phases of terrorism cases, providing guidance or supervision on
the legal and strategic implications of various investigative techniques. In the present
chapter, the role of prosecutors in terrorism cases involving the use of the Internet by
terrorists is considered, with a view to identifying, from a prosecutor’s perspective,
common challenges or obstacles and strategies and approaches that have been proven
to be effective in the successful prosecution of perpetrators.
B. A rule-of-law approach to criminal prosecutions
339. An investigation and prosecution that is not conducted in full accordance with
the principles generally associated with the rule of law and international human rights
standards risks the integrity of the very fabric of the social and institutional norms and
structures that terrorists themselves seek to undermine. It is therefore of fundamental
importance that any prosecution of the perpetrators of terrorist acts be conducted with
the utmost attention to the need to ensure a fair trial and fair treatment of accused
persons.
340. The well-recognized principle that suspected terrorists should be afforded the
same procedural safeguards under the criminal law as any other suspected criminals is
strongly embedded and reflected in the universal instruments against terrorism and at
the political level internationally. Just one of many examples of high-level recognition
of this principle is General Assembly resolution 59/195, on human rights and terrorism,
in which the Assembly highlighted the need for enhanced international cooperation
101
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
measures against terrorism, in conformity with international law, including international
human rights and humanitarian law. In addition to incorporating this fundamental
principal at a political level, the United Nations, through its Special Rapporteur on the
promotion and protection of human rights and fundamental freedoms while countering
terrorism, regularly reports to the Human Rights Council and to the General Assembly
on areas of concern related to the human rights aspects of criminal justice measures
targeting terrorism and makes recommendations for remedial action by relevant actors.
Issues raised by the Special Rapporteur have included those related to the detention
and charging of suspects.158
341. There are several publications dealing specifically with, and aimed at, promoting
respect for human rights and the rule of law within the remit of prosecutors and criminal
justice officers involved in terrorism prosecutions. In 2003 the Office of the United
Nations High Commissioner for Human Rights produced the Digest of Jurisprudence of
the United Nations and Regional Organizations on the Protection of Human Rights while
Countering Terrorism. Within the Council of Europe, which has fully recognized and
integrated the obligation to implement the protection of human rights as a fundamental
principle into its instruments dealing with crime prevention and criminal justice issues,
including terrorism, this principle is reaffirmed in the Guidelines of the Committee of
Ministers of the Council of Europe on Human Rights and the Fight against Terrorism,
adopted by the Committee of Ministers on 11 July 2002.159 These documents provide
valuable guidance for prosecutors working in the counter-terrorism field.
C. Role of prosecutors in terrorism cases
342. The role of the prosecutor in the conduct of criminal proceedings, including
terrorism cases, varies between countries. In some countries, particularly civil-law juris-
dictions, prosecutors have formal responsibility for overseeing the conduct of criminal
investigations, supervising teams of investigators throughout, making decisions on search
and surveillance activities and the laying of charges or indictments and dealing with
international cooperation issues and the conduct of proceedings before the courts.
343. In an inquisitorial judicial system like the French one, for example, the prosecu-
tor is generally tasked with beginning the legal action and with initiating preliminary
investigations, defining the scope of the crimes; however, an examining judge, or juge
d’instruction, will lead the formal judicial investigation, collecting and examining evi-
dence. When the culpability of the subject can be excluded, the examining judge will
close proceedings; otherwise, the subject will be committed for trial before a different
judge. In terrorism cases, in addition to presenting the prosecution case to a judge, the
chief prosecutor may petition or submit a motion for further investigation.
158 Ibid.
159Any text created within the Council of Europe, irrespective of whether it is a binding convention or a “soft law”
instrument, such as a recommendation or resolution issued by the Parliamentary Assembly or the Committee of
Ministers, including any guidelines on various topics, must always be in compliance with the extensive case law of the
102
European Court of Human Rights on the respective issue.
CHAPTER VI. Prosecutions
344. In other countries, particularly common-law jurisdictions, prosecutors have tra-
ditionally had less direct involvement with, or responsibility for, the conduct of criminal
investigations, which are usually led by law enforcement agencies. Typically, in these
jurisdictions, prosecutors assume formal responsibility for the conduct of prosecutions
at the point of charging or the laying of indictments through to the final disposition of
the proceedings. For example, in Nigeria, the national police are responsible for con-
ducting criminal investigations. Upon completion, cases are referred to a prosecution
authority that hold responsibility for the laying of charges and the conduct of the
criminal proceedings.
345. A similar approach is taken in Indonesia, where a separation exists with regard
to the investigation and prosecution of a criminal case. After the commencement of a
criminal investigation, the investigator must report the progress of the case to the public
prosecutor (art. 109, para. 1, of the Indonesian Criminal Procedure Code) and, once
the investigation is concluded, must hand the case files over to the Public Prosecutor
(art. 110, para. 1, of the Criminal Procedure Code), who will decide whether a case
can be brought to trial (art. 139 of the Criminal Procedure Code).
346. Regardless of the specificities of the particular jurisdiction, however, the role
played by prosecutors in terrorism cases continues to evolve to meet the increased
demands placed on them by ongoing developments in the type, methods and complex-
ity of terrorism-related crimes, counter-terrorism laws, new investigative techniques and
international cooperation arrangements.
347. Experience shows that prosecutors are increasingly being required to play a more
direct role in the investigation of crimes, not merely during the prosecution phase.
Prosecutors are increasingly adopting a more technical and strategic role, not only
informing counter-terrorism policy and legislation but also providing legal and strategic
advice and guidance on legal issues during investigations that influence the likely suc-
cess of any resulting prosecution. Experience shows that they are likely to undertake
their role as part of a multidisciplinary/multijurisdictional team.160
348. Moreover, with increased visibility and scrutiny of terrorism prosecutions, includ-
ing media coverage and monitoring by human rights groups and international bodies,
prosecutors play a crucial role in ensuring that investigations and prosecutions not only
are, but are seen to be, conducted in a way that is fair and efficient and that upholds
international human rights standards.
D. The investigative phase
349. During the intelligence-gathering or investigative phase of counter-terrorism
operations, prosecutors are often called upon to provide legal advice on issues related
to the use of specialized investigative techniques.
160Yvon Dandurand, “The role of prosecutors in promoting and strengthening the rule of law”, paper presented
to the Second World Summit of Attorneys General, Prosecutors General and Chief Prosecutors, held in Doha from 14
to 16 November 2005.
103
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
1. Specialized investigative techniques
350. While new or emerging technology and search and surveillance techniques offer
intelligence and law enforcement agencies enhanced opportunities to target terrorist
activities on the Internet, they also carry legal risks in the context of prosecutions, to
which prosecutors need to remain constantly vigilant. Moreover, owing to differences
in national laws related to the collection and admission of evidence, these risks are
higher when actions giving rise to evidence occur in a different jurisdiction from that
in which the prosecution will be conducted. At the European level, the Council of
Europe, being aware of these risks and the implied human rights issues, has elaborated
a recommendation on special investigation techniques in relation to serious crimes,
including acts of terrorism,161 which contains, inter alia, general principles, operational
guidelines and a chapter on international cooperation.
351. The legal risks related to emerging investigative techniques reinforce the need
for prosecutors to be actively involved, at the earliest possible stage, in decisions taken
during the investigative phase of terrorism cases to ensure that actions taken in the
collection of potential evidence do not compromise the success of any subsequent
prosecution. Issues related to the admissibility of evidence are dealt with in more detail
elsewhere in the present chapter.
352. Constant and rapid changes in the technological capabilities of intelligence and
law enforcement agencies with respect to surveillance and the monitoring and collection
of intelligence or evidence of terrorist activity highlight the critical importance of the
prosecutor’s role in providing advice to investigators on the legal implications of such
activities for prosecutions. Moreover, owing to the increasing likelihood, particularly in
cases involving Internet-related activities across national borders, of authorities being
required to coordinate and collaborate with foreign counterparts on related legal issues
(e.g. preservation of Internet-related data held by ISPs), it is increasingly important
that prosecutors be consulted and involved in decisions about investigative strategies at
the earliest possible opportunity.
2. The use of multidisciplinary teams
353. Increasingly, authorities are turning to the use of multidisciplinary/multiagency
teams, comprising law enforcement and intelligence agencies, as well as prosecutors, in
the interdiction, disruption and prosecution of terrorist activities. The high level of trust,
coordination and communication that was identified by the expert group meeting as
vital to effective cooperation at an international level also needs to exist between national
law enforcement, intelligence and prosecuting agencies. While there is no single approach
through which these elements can be fostered, a clear understanding of the mandates
and roles of contributing agencies, appropriate information-sharing powers and mecha-
nisms (perhaps based on memorandums of understanding or similar arrangements) and
regular coordination meetings or training activities will serve to strengthen these impor-
tant national partnerships.
104
161 Committee of Ministers of the Council of Europe, Recommendation Rec (2005)10 (20 April 2005).
CHAPTER VI. Prosecutions
354. While there are differences in how authorities in different countries coordinate
and operate multiagency investigations, there are nevertheless broad similarities. In the
United States, a task-force approach, using multidisciplinary teams from all relevant
agencies, including prosecutors, is employed in conducting investigations related to ter-
rorism in that country.
355. Under this approach, prosecutors are joined to, and form an integral part of,
teams of intelligence, law enforcement and other specialist agencies that constantly
monitor, assess and reassess different aspects of investigations into suspected terrorist
activity. Counter-terrorism task forces and/or joint terrorism task forces coordinate the
efforts of local, state and federal law enforcement agencies and prosecutors’ offices.
Many state and federal prosecution offices participate in such task forces, with methods
and tasks varying from attendance at inter-agency meetings to the collocation of staff
and legal advice in obtaining search warrants to reviewing cases and making recom-
mendations on charges.162
356. In Canada, authorities use integrated national security enforcement teams
(INSETs). In the Namouh case, the INSET comprised the Royal Canadian Mounted
Police, the Canada Border Services Agency, the Canadian Security Intelligence Service,
the Quebec Provincial Police, the Montreal Police Service and the Public Prosecution
Service of Canada.
357. In Japan, it is common practice in terrorism-related investigations for police, even
though they are legally independent, to report the case to the public prosecutor in the
early stages of an investigation and to consult with them when evaluating evidence and
interpreting laws.163 A similar approach applies in Egypt.
358. In order to enhance the effectiveness and efficiency of counter-terrorism prosecu-
tions, Governments often develop, within national prosecution agencies, specialized
departments or units to deal with terrorism-related cases. This is the case in Indonesia,
which has adopted a number of special measures, including the creation of a task force
within the Attorney General’s office on the prosecution of terrorism and transnational
crimes. This task force is charged with facilitating and expediting law enforcement,
during both the investigative stage, by coordinating with police (e.g. the involvement
of state prosecutors during the interrogation of suspects), and during any subsequent
prosecution, up to the final execution of the court’s ruling.
359. While there may be variations at the international level in the means by which
prosecutors become involved in, and integrated into, criminal investigations, the general
approach adopted in many countries highlights the desirability of such integration and
of a multidisciplinary, holistic approach to strategic and operational decisions taken
during the investigative phase of terrorism cases.
162 M. Elaine Nugent and others, Local Prosecutors’ Response to Terrorism (Alexandria, Virginia, American Prosecutors
Research Institute, 2005).
163 United Nations Office on Drugs and Crime, Digest of Terrorist Cases, para. 212.
105
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
E. International cooperation
360. Issues related to international cooperation have already been dealt with in chapter
VI above and need not be restated here. Specific issues of relevance to prosecutors,
raised by experts at the expert group meeting, in cases involving elements of interna-
tional cooperation relate to the mediation and resolution of issues related to the mode
of cooperation, jurisdictional issues, dual-criminality requirements and the admissibility
of foreign evidence, which experience shows presents an ongoing challenge. Given the
common interest of all States in the successful prosecution of crimes related to terror-
ism, it is important not only that States have in place the legislative frameworks to
facilitate this cooperation but also that prosecutors deal with the resolution of these
issues in a proactive and collaborative manner.
F. The charging phase
1. Decisions whether to charge
361. In most countries, prosecutors have wide discretion in deciding whether to insti-
tute criminal proceedings and with which charges. Often such decisions are taken in
accordance with guidelines or codes designed to ensure the fair, transparent and con-
sistent exercise of this discretion. For example, in the United Kingdom, prosecutors
make these decisions in accordance with the Code for Crown Prosecutors, which pro-
vides a threshold for charging based on evidential sufficiency and public interest. Pros-
ecutors must be satisfied that the evidence before them discloses a “realistic prospect
of conviction” before charging a suspect with a particular offence.164 A similar approach
applies in Egypt.
362. In the terrorism context, the public interest element of assessments of whether
to charge is likely to be very strong, given the need, whenever possible, to prosecute
terrorist acts or related crimes to protect the public and deter similar offences. In many
cases, issues related to the sufficiency of available evidence may be determining factors
and may be affected by the ability to use intelligence-based evidence without compro-
mising its sources and methods of collection or other investigations. For this reason, in
some cases prosecutors may need to elect to charge suspects with non-terrorism-specific
charges in order to protect the integrity of intelligence material.
2. Use of general or non-terrorism specific criminal offences
363. In cases in which they need to intervene to prevent the commission of terrorist
acts before there is sufficient evidence available to initiate a prosecution for the terrorist
acts being planned, authorities might well need to rely upon other criminal offence
provisions to provide the legal basis for their actions. In many cases in which suspected
164 Crown Prosecution Service, “The Code for Crown Prosecutors” (London, 2010). Available from www.cps.gov.
106
uk/publications/docs/code2010english.pdf.
CHAPTER VI. Prosecutions
terrorists have used the Internet as part of criminal activities, authorities have success-
fully used criminal offences such as solicitation, conspiracy or participating in, or pro-
viding material support to, terrorist groups, rather than substantive offences related to
terrorist acts being planned. In this context, the availability of offences such as solicita-
tion, conspiracy or criminal association is particularly useful. In some cases, authorities
have been able to use other general criminal offences such as fraud or offences related
to the possession or use of unlawful articles (e.g. false identity or travel documents,
weapons), which provide investigators and prosecutors with an opportunity to disrupt
or compromise the activities of terrorist groups before their planned attacks or activities
can be carried out.
G. The trial phase: evidential issues
1. Issues related to the use of intelligence-based evidence
364. The integration of intelligence activities into criminal justice systems remains a
fundamental problem for authorities in dealing with terrorism. As previously stated, in
many terrorism cases evidence used by the prosecution has been derived from
intelligence-based sources. A common challenge for authorities in all countries when
prosecuting terrorism-related cases is how to protect the sensitive material underlying
intelligence-based evidence while meeting their obligation to ensure a fair trial and
effective defence for accused persons, including the obligation to disclose all material
parts of the prosecution case to the defence.
2. Issues related to the collection and use of digital evidence
365. In terrorism cases involving the use of computers, similar devices or the Internet,
digital evidence will be an important part of the prosecution case. In cases in which
suspects were not physically present at the location where a terrorist act occurred, but
nevertheless supported the commission of the act via some action on the Internet, the
presentation of evidence showing their “digital fingerprints” can be compelling evidence
of their complicity and culpability.
366. Experience shows that the use of digital evidence invariably gives rise to issues
related to admissibility. It is therefore critical that great care be taken throughout the
investigation and prosecution of the case to ensure that the methods used for its col-
lection, preservation, analysis and production are in full conformity with the relevant
rules of evidence or procedure, and that they follow established good practice.
367. Digital evidence can be technically complex and involve terms and concepts that
are unfamiliar to the judge, jury or tribunal hearing the case. Prosecutors need to
consider, in close coordination with investigators and experts, how best to present such
evidence in a way that is easily understood and compelling. In this regard, the use of
diagrams and similar visual aides showing the movement of data or linkages between
computers and users might be beneficial.
107
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
368. As part of its case in prosecutions based on some form of computer use, the
prosecution will need to identify the defendant as the user, at the material time, of the
computer, device or Internet service used in the commission of the crime with which
he or she is charged, and establish links proving that fact. There are several ways in
which this can be done: (a) the defendant might make a confession or admit this fact;
(b) his or her presence at the computer might be established by circumstantial means
(e.g. he or she was the only person present where the computer was located or at the
material time, he or she was the registered user of the relevant hardware or software,
or there is other information on the computer that is solely within the defendant’s
knowledge); or (c) the link can be established by analysing the contents of the device/
service the defendant was alleged to have used. This might involve the prosecutor pro-
ducing evidence about specific characteristics of the material on the device (e.g. a
document) or a comment made in an intercepted communication that are unique to
the defendant. Finally, although they are not infallible, time and date stamps on digital
files can be a compelling method of linking the defendant to the relevant device at
times material to the commission of a crime.165
369. While the specifics may vary, the general approach taken by courts in many
countries when determining the admissibility of evidence in criminal trials is based on
relevance and reliability: is the evidence which a party seeks to adduce relevant, and is
it reliable? In the case of relevant digital evidence, the challenge for prosecutors in many
cases will be to satisfy the court of its reliability, both in terms of content and the methods
used to collect and bring it before the court. The process of satisfying a court that digital
evidence is admissible often involves proving the lawfulness of the methods used to collect
it and preserve its integrity from the point at which it is collected through to its production
in court. This is known as the “chain of custody” or “chain of evidence”: the procedures,
both operational and legal, for preserving the integrity of evidence. In most countries,
there are strict legal rules relating to the chain of custody, which require evidence to be
immediately recorded, centralized, sealed and protected against contamination pending
trial, in some cases under the supervision of a judicial officer.
370. In terrorism cases involving the collection and use of intercepted communications
or digital forensic evidence, prosecutors should ensure, in close collaboration with intel-
ligence and/or law enforcement agencies, that such evidence has been collected in a
lawful manner and preserved and produced in a manner that meets the evidential
requirements of the jurisdiction in which it will finally be used. Collecting and produc-
ing digital data as admissible evidence, especially when it is held remotely by a suspect
or related third party in other jurisdictions, is a challenging task for both investigators
and prosecutors. In addition to the technical complexities of capturing and preserving
the integrity of required data, the need in some situations to rely upon the cooperation
of foreign intelligence, law enforcement or prosecuting agencies, acting under different
laws and procedures regulating the collection and use of such data, can make such
processes lengthy and resource-intensive.
165 United States Department of Justice, Office of Justice Programs, National Institute of Justice, Digital Evidence
in the Courtroom: A Guide for Law Enforcement and Prosecutors (2007), chap. 4, sect. IV. Available from www.ncjrs.gov/
108
pdffiles1/nij/211314.pdf.
CHAPTER VI. Prosecutions
371. In investigations involving the collection of digital data located entirely within
one jurisdiction, issues relating to its admissibility as evidence are likely to centre largely
to the legal basis on which it was collected and its subsequent handling and preserva-
tion (i.e. the chain of custody or evidence). As always, care needs to be taken to ensure
that the legal basis for its collection, forensic examination, preservation and production
is in full accordance with applicable rules and procedures relating to the admissibility
of evidence.
372. In the case of digital data collected in one or more jurisdictions for use in crimi-
nal proceedings in a different jurisdiction, the situation is considerably more complicated
and requires careful attention on the part of investigators and prosecutors.
373. As soon as practicable after identifying the party holding and the location of data
in a foreign jurisdiction relevant to an investigation, investigators and prosecutors should
explore both informal and formal means of obtaining and preserving it for evidential
purposes. Whenever possible and feasible, informal channels to secure the data for later
use as evidence should be favoured, provided that the methods by which it is collected,
preserved and transmitted to the receiving country comply with applicable evidential
rules and procedures. In order to collect such data, investigators may need to consider
requesting foreign counterparts to obtain search warrants to search and seize data or
might need to consider using other means (e.g. publicly available web pages) or the
use of voluntary foreign witnesses.
374. A case from Germany, concluded in 2009 and relating to the successful prosecu-
tion of four members of the Islamic Jihad Union, illustrates the size and complexity of
many terrorism investigations and prosecutions. The case, which involved an investiga-
tion carried out over nine months, involved more than 500 police officers, many hours
of electronic interception and surveillance and the collection of many exhibits, as well
as extensive international cooperation between German authorities and their counter-
parts in Turkey and the United States. The size and complexity of the case highlight
the significant resources that can be required to undertake investigations and prosecu-
tions and the necessity and strengths of a team approach.
Fritz Gelowicz, Adem Yilmaz, Daniel Schneider and Atilla Selek
In September 2007, after an intensive investigation, German authorities, acting on intelli-
gence received from their counterparts in the United States, arrested four members of the
Islamic Jihad Union (often referred to as the “Sauerland cell”), who were in the final stages
of preparations for a series of bombings at various public locations in Germany. Intended
targets included bars and nightclubs in multiple locations in Munich, Cologne, Frankfurt,
Dusseldorf and Dortmund, as well as the United States Air Force base at Ramstein. The
total volume of explosive material that the defendants thought they had collected (it had
been covertly replaced by authorities with a weaker harmless substance) was massive, poten-
tially enough to exceed the force of the terrorist bombings in Madrid (2004) and London
(2005).
109
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
Three of the defendants—Gelowicz, Schneider and Selek—were German nationals; the
fourth, Yilmaz, was a Turkish national. Over the course of several months, the defendants
acquired through legitimate sources 780 kg of hydrogen peroxide. On 4 September 2007,
the authorities arrested the defendants when they met at a holiday home located in the
Sauerland region of Germany and started to “cook” the hydrogen peroxide by adding other
ingredients to heighten its explosive effect. (Unbeknown to the defendants, authorities had
earlier replaced the hydrogen peroxide solution with a weaker, harmless solution.)
In August 2008, indictments were laid against Gelowicz, Schneider and Yilmaz by federal
prosecutors. Selek was extradited from Turkey in November 2008 on the basis of an extradi-
tion request under the European Convention on Extradition and was indicted in December
2008. The charges included conspiracy to commit murder, preparing to carry out an explo-
sion and membership of a terrorist organization.
The trial of all four defendants commenced in April 2009, lasting for three months before
the defendants elected to admit the charges. The volume of evidence that the prosecution
intended to present was huge, comprising 521 loose-leaf folders (enough to fill a 42-metre
single shelf) and an estimated 219 witnesses. A large part of the prosecution case related
to extensive electronic monitoring and surveillance that had been undertaken by German
authorities during the investigation. Electronic investigative techniques included the use of
wiretaps of audio conversations between the defendants and listening devices planted in
vehicles and the house where they met to prepare the hydrogen peroxide for the explosive
device, as well as the interception of their e-mail traffic. The prosecution proposed produc-
ing extensive digital evidence; however, there had been clear signs during the plot that the
defendants were taking precautions against surveillance or monitoring. Over the course of
the nine-month investigation, authorities faced a number of technical challenges. For exam-
ple, the defendants had communicated using e-mail drafting (i.e. opening and reading draft
messages in e-mail accounts) to prevent wiretapping by law enforcement agencies, and had
used the insecure wireless LAN connections of innocent private citizens and encrypted com-
munication via VoIP providers (e.g. Skype).
In the case of Gelowicz, the alleged ringleader of the group, he had used random Internet
access via unsecured private residential LAN networks, employed at least 14 different e-mail
accounts, changed vehicle licence plates and used a police scanner to monitor police radio
traffic. He had protected data on his computer using encryption, which forensic experts
tried without success to decrypt and access. Gelowicz eventually supplied the encryption
key, but investigators found only traces of shredded data.
During the trial, the defence challenged the validity of the prosecution, questioning the
basis for the investigation, which it asserted was inherently flawed, being based on United
States intelligence, which it asserted included electronic monitoring of the defendants’ com-
munications, which was unlawful and had been provided in breach of their rights under
the Constitution of Germany.
On 4 March 2010, the four defendants were found guilty of all charges and sentenced:
Gelowicz and Schneider to 12 years of imprisonment, Yilmaz to 11 years of imprisonment
and Selek to 5 years of imprisonment.
3. Issues related to use of foreign evidence
375. Legal principles and procedures related to the collection and admissibility of
110
evidence in criminal proceedings often differ between jurisdictions. One of the major
CHAPTER VI. Prosecutions
challenges confronting investigators and prosecutors in any criminal investigation and
prosecution with a cross-border character (in both the requested and requesting coun-
tries) is ensuring that necessary evidence is collected, preserved, transmitted and pro-
duced in accordance with the legal procedures and rules of evidence applicable in the
respective jurisdictions in a form that is admissible where the trial will take place.
376. The process of “mediating” different aspects of evidence between countries can
be a complex, time-consuming process but is a critical factor in the success of prosecu-
tions. Any legal deficiencies in the methods by which evidence ultimately used at trial
is collected or produced will almost certainly be challenged by defence lawyers.
377. A useful example, highlighting the types of issues that can arise in this context,
can be found in the Belgian case of Malika el Aroud and Others, which related to the
activities of a group of defendants involved in establishing and administering several
websites used to disseminate terrorist propaganda and information useful to terrorists
as well as serve as a forum for communication. Several of the defendants lived in
Belgium, but the primary website on which they carried out their activities (minbar-sos.
com) was hosted in Canada.
Malika el Aroud and Others
Introduction
In December 2008, after lengthy, intensive and complex investigations coordinated between
intelligence, law enforcement and prosecution authorities in France, Belgium, Switzerland,
Italy, Turkey, the United States and Canada, a number of persons with suspected links to
the Al-Qaida terrorist organization were arrested and charged in France and Belgium with
a range of criminal charges, including participation as a member of a terrorist group, financ-
ing of terrorism and providing information and material means to a terrorist group.
In carrying out the alleged acts forming the basis of these charges, the suspects had made
extensive use of the Internet. The investigation into their activities involved complex electronic
surveillance, wiretaps and other forms of monitoring by intelligence and law enforcement
agencies. In successfully bringing the case to a conclusion, authorities in several jurisdictions
were required to cooperate, on both a formal and an informal basis.
The case is an example of highly successful cooperation in criminal prosecutions related to
terrorism with Internet-related aspects between national authorities across participating
States, and highlights many aspects of good practice referred to in the present publication.
References to these aspects are made throughout chapters V and VI, on international coop-
eration and prosecutions.
The case, which had linkages to other cases in several countries, revolved primarily around
the activities of Malika el Aroud, a female Belgian national of Moroccan descent, and her
husband, Moez Garsallaoui, a Tunisian national. Both were actively involved in the dissemi-
nation of radical jihadist propaganda and the recruitment, organization, direction and funding
of a group of young men from Belgium and France to take part as jihadists in Afghanistan
and elsewhere.
111
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
While some of these activities were undertaken using other methods, the couple used the
Internet extensively to undertake these actions, including for communication. In addition to
El Aroud and Moez Garsallaoui (who, together with an accomplice, Hicham Beyayo, were
tried in absentia), other defendants tried were Ali el Ghanouti, Said Arissi, Jean-Christophe
Trefois, Abdulaziz Bastin, Mohamed el Amin-Bastin and Hicham Bouhali Zrioul
The Belgian case has close linkages to both a French case, involving the defendants Walid
Othmani Hamadi Aziri, Samira Ghamri Melouk, Hicham Berrached and Youssef el Morabit,
who were tried and convicted before the Tribunal de Grande Instance de Paris,a and an
investigation and prosecution in Italy relating to Bassam Avachi and Raphaël Gendron.
Background
In August 2007, Belgian authorities received information from their French counterparts
concerning the activities on the Minbar SOS website (itself hosted in Canada), which they
suspected was being used to disseminate Salafist propaganda calling for jihad against France.
The site was allegedly administered by El Aroud and Garsallaoui. As the investigation widened,
other similar websites were identified.
Authorities suspected that El Aroud and Garsallaoui, acting together through the site, were
identifying and recruiting individuals from Belgium to fight in Afghanistan. El Aroud posted
inflammatory material calling upon young people to sign up for jihad.
Malika el Aroud and Moez Garsallaoui
Malika el Aroud and Moez Garsallaoui were already well known to European counter-
terrorism agencies. In 2003, El Aroud had been tried and acquitted by a court in Belgium
of alleged involvement in a jihadist logistical support network used in the murder of an
anti-Taliban resistance leader in September 2001. One of the two assailants was El Aroud’s
first husband.
In 2007, El Aroud was prosecuted in Switzerland, along with Garsallaoui, her second hus-
band, for providing “support to a criminal organization” and “public incitement to violence
and crime” through different websites they had both set up in Switzerland. She was con-
victed and sentenced to a six-month suspended sentence by the Tribunal pénal fédéral de
Bellinzone.
On 21 December 2007, El Aroud was arrested in Belgium on suspicion that she had attempted
to help a prison inmate, Nizar T., to escape from custody; she was released after 24 hours,
however, owing to insufficient evidence. In 2004, Nizar T. had been convicted by a court
in Belgium and sentenced to 10 years of imprisonment for preparing a terrorist attack on
the United States military base at Kleine-Brogel in 2007. This arrest occurred while investiga-
tions were already under way in relation to her suspected activities on Minbar SOS.
The websites
The websites established by El Aroud, including Minbar SOS, were used as a platform for
posting propaganda (e.g. videos and photographs), circulating books and publications and
communicating. Each of the members was provided with a login/pseudonym and an elec-
tronic address so that they could exchange private messages, sometimes encrypted in closed
chat rooms hosted on the sites. These would contain instructions, intelligence, propaganda
and constant calls for massive jihad. Some material contained clear references to Al-Qaida
leadership and included postings of attacks on United States troops in Iraq.
112
CHAPTER VI. Prosecutions
Messages with explicit threats (e.g. a message entitled “Against French terrorism in Afghani-
stan, only one solution”) were posted, along with a map of the Paris RER commuter train
network, on which some of the main stations had been highlighted with radioactivity or
biological contamination symbols. Some messages gave explicit instructions on how to trans-
fer funds to members of the jihad. By the end of 2008, the primary site, Minbar SOS, had
more than 1,400 subscribers.
As part of a joint investigation, Belgian and French authorities intercepted communications
on websites, e-mails and phone calls, and monitored and traced financial flows. Neverthe-
less, while Belgian security agencies closely monitored Internet activity on the Minbar SOS
website aimed at recruiting fighters for Afghanistan, they could do little to prevent El Aroud
from administering the site, owing to strong freedom of speech protection under Belgian
law.
The French tribunal, which eventually dealt with judicial proceedings in that country related
to the case, observed, when referring to the websites:
The activity on these websites cannot be analysed as a simple search for information
or intelligence, but on the contrary, characterizes a conscious participation in a terrorist-
oriented undertaking/mission.
In addition, in testimony at later trials, defendants Saïd Arissi and Hicham Beyayo stated,
respectively, “I consider myself as a victim of the Internet propaganda” and “ websites like
Ribaat and Minbar SOS influence people like me who went to fight”, illustrating the
influential effect the activities undertaken through the site had on some individuals.
In a rare interview, for an article that appeared in The New York Times on 28 May 2008,
El Aroud called herself “a female holy warrior for Al-Qaida. She insists (…) she has no
intention of taking up arms herself. Rather, she bullies Muslim men to go and fight and
rallies women to join the cause. ‘It’s not my role to set off bombs—that’s ridiculous … I
have a weapon. It’s to write. It’s to speak out. That’s my jihad. You can do many things
with words. Writing is also a bomb.’”b
Travel of recruits to the Federally Administered Tribal Areas of Pakistan
In addition to the activities conducted via the websites, Garsallaoui also toured the immigrant
neighbourhoods of Brussels to recruit people face-to-face. Hicham Beyayo, a 23-year-old
Belgian national of Moroccan descent who was arrested in the case and was a Minbar SOS
site administrator before travelling to Pakistan, admitted being recruited in that way.
Garsallaoui’s recruiting was not restricted to Belgium; he also recruited two French subscrib-
ers to Minbar SOS. One of those recruits, who travelled to the Federally Administered Tribal
Areas of Pakistan and was later arrested, referred to the calls to “jihad” on Minbar SOS as
“incessant” and said that the video propaganda he viewed on the site made him want to
volunteer.
In December 2007, Garsallaoui and six recruits, including Hicham Beyayo, Ali el Ghanouti
and Y. Harrizi, travelled to the Federally Administered Tribal Areas via Turkey and the Islamic
Republic of Iran. The group remained there until the second half of 2008. While there,
Garsallaoui was in regular contact with El Aroud via e-mail and sometimes Skype. In addi-
tion to sending photographs and other propaganda material, he posted statements and
periodically tuned in to the forums on Minbar SOS.
113
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
On 26 September 2008, Garsallaoui posted an online statement on Minbar SOS calling for
attacks in Europe: “The solution, my brothers and sisters, is not fatwas but boooooooms”,
the posting stated.
The arrests
Over a period of some months in the second half of 2008, some of the suspects began
returning to Belgium. Belgian security services were placed on alert after El-Ghanouti and
Harrizi returned from the Federally Administered Tribal Areas, and on 4 December 2008
Beyayo himself returned to Belgium.
Differing explanations are offered for the reasons the recruits returned to Belgium at this
time. Some of the suspects suggested dissatisfaction with the treatment and conditions in
the Federally Administered Tribal Areas, including restrictions on their ability to participate
in jihad, and denied the existence of any “sleeper cell” aimed at carrying out attacks in
Belgium. Belgian authorities, however, considered indications from intercepted communica-
tions as providing strong grounds for suspecting that the group might be in the final stages
of planning a suicide terrorist attack (possibly using Hicham Beyayo) within Belgium, which
required immediate action.
On 11 December, a week after Beyayo’s return, Belgian authorities raided 16 locations within
Belgium and arrested nine suspects, including El Aroud, Garsallaoui and Beyayo. Similar
operations were conducted in France and Italy.
Criminal proceedings
Belgium
At trial, defence lawyers challenged different aspects of the prosecution case, including
procedural grounds and the admissibility of certain evidence, including Internet-related data
obtained on an informal basis from the FBI relating to ISPs based in the United States. Issues
related to such evidence are dealt with in more detail later in the present publication.
Beyayo had been interviewed by authorities in Morocco on 20 May 2008. His defence
lawyers argued that a violation of the right to a fair trial had occurred, based on suspicions
that torture had been carried out by the Moroccan authorities on detainees suspected of
terrorism. The court rejected those arguments.
Activities of Bryan Neal Vinas (United States)
In January 2009, United States national Bryan Neal Vinas travelled to Afghanistan, where
he attempted to kill American soldiers during an Al-Qaida rocket attack against a military
base. He was later arrested and returned to the United States, where he was charged with
conspiring to murder United States nationals, providing material support to Al-Qaida and
receiving military training from the group. Vinas pleaded guilty and received a prison term.
Belgian authorities prosecuting Beyayo, an accomplice of El Aroud, produced evidence from
Vinas’ trial to establish the extent of their activities and involvement in the Al-Qaida network.
In statements, Vinas admitted to having met some of the Belgian recruits. The defence
challenged the admissibility of this evidence on a number of grounds, but those arguments
were rejected by the court.
114
CHAPTER VI. Prosecutions
Trial outcome
Following trial, on 10 May 2010, the Tribunal de Première Instance de Bruxelles dealt with
the cases of nine defendants who had been prosecuted on different charges, falling into
three groups: A, B and C.
The group A and C charges, respectively, comprised participation as a leading member of
a terrorist group and participation in the activities of a terrorist group, including by providing
information or material means or through any form of financing of a terrorist group’s activ-
ity, knowing that such participation would contribute to the commission of a crime or
offence by that group.
The group B charges comprised the commission of offences or the provision of assistance
in executing offences by means of donations, promises, threats, abuse of authority or power,
plots or schemes with the intent to commit crimes against people or assets in order to
cause serious harm, as well as offences that, by their nature or context, could seriously harm
a country or an international organization and that were committed intentionally with the
aim of seriously intimidating a population or unduly forcing public authorities or an inter-
national organization to take action, or of seriously destabilizing or destroying the funda-
mental political, constitutional, economic or social structures of a country or an international
organization.
The sentences under the group A charges were as follows:
""
Malika el Aroud: eight years of imprisonment and a €5,000 fine
""
Moez Garsallaoui: eight years of imprisonment and a €5,000 fine (in absentia)
""
Hicham Beyayo: five years of imprisonment and a €1,000 fine (in absentia).
The sentences under the group B charges were as follows:
""
Ali el Ghanouti: acquitted
""
Said Arissi: acquitted.
The sentences under the group C charges were as follows:
""
Ali el Ghanouti: three years of imprisonment and a €500 fine
""
Said Arissi: 40 months of imprisonment and a €500 fine
""
Hicham Bouhali Zrioul: five years of imprisonment and a €2,000 fine (in absentia)
""
Abdulaziz Bastin: 40 months imprisonment and a €500 fine
""
Mohamed el Amin-Bastin: 40 months of imprisonment and a €500 fine
""
Jean-Christophe Trefois: acquitted.
France
In France, five suspects (all French nationals of North African descent) were tried before the
Tribunal de Grande Instance de Paris. Walid Othmani, Hamadi Aziri, Samira Ghamri Melouk,
Hicham Berrached and Youssef el Morabit were charged with a variety of offences: financing
of terrorism, conspiracy to commit a terrorist act and participating in a group constituted
for the purpose of preparing a terrorist act specified in article 421-1 of the French Penal
Code.
115
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
Italy
Bassam Ayachi and Raphaël Gendron (both French nationals) were charged by Italian authori-
ties with criminal association with the aim of terrorism under article 207 bis, paragraph 1,
of the Italian Criminal Code, which provides a penalty of 7 to 15 years of imprisonment
for anyone found guilty of constituting, promoting, organizing, managing or financing
groups that intend to carry out violent activities in furtherance of terrorist aims or the sub-
version of the democratic structure of the state, and a term of imprisonment from 5 to 10
years for individuals who associate with such groups.
The case established links between the two defendants and some of the defendants in the
Belgian proceedings, as well as common elements of evidence, including evidence on a DVD
of a suicide note written by one of the Belgian suspects.
On 3 June 2011, Ayachi and Gendron were sentenced to eight years of imprisonment.
Source: Eurojust, Terrorism Convictions Monitor, Issue 8, September 2010
a Judgement 18 February 2011 (No. d’affaire 1015239014).
b See “Al Qaeda warrior uses Internet to Rally Women”, The New York Times (28 May 2008). Available from
378. In the El Aroud case, the prosecution produced evidence of Internet data, related
to postings and chat room discussions. In the case of the e-mails (the latter sent from
accounts held by Yahoo and Microsoft), the data was held on servers in the United
States. Following an informal request for assistance, Belgian authorities were provided
(within two weeks) with a CD by the FBI containing the data related to the specified
e-mail accounts and other related accounts. The FBI stipulated that it had been pro-
vided by Yahoo and Microsoft voluntarily, as permitted by the provisions of the United
States Patriot Act.
379. The defence challenged the admissibility of this evidence, asserting that the pro-
cedures used to collect, transmit and produce the evidence were unlawful, as it was
collected in the absence of a search warrant, and on the basis that the informal pro-
cedures used did not follow the usual methods for international exchange of judicial
information, thereby contravening article 7, paragraph 1, of Belgium’s law of 9 Decem-
ber 2004 on international mutual assistance in criminal matters.
380. The Court rejected this argument, holding that: (a) the exchange of information
had not occurred within the framework of mutual legal assistance; (b) no examining judge
had been appointed to the case at the material time, which was being handled on an
informal police-to-police basis; and (c) the procedure used was justified by the emergency
aspect of the circumstances (i.e. the discovery of a suicide note posted on the Minbar
SOS website by one of the suspects, leading to the belief that an attack on French soil
orchestrated by Malika el Aroud and her conspirators was imminent). The Court held
that on those grounds the Federal Magistrate was justified in concluding that this
116
emergency police cooperation was founded on grounds of article 15, paragraph (b), of
CHAPTER VI. Prosecutions
the International Convention for the Suppression of Terrorist Bombings (1997),166 which
provides for “exchanging accurate and verified information in accordance with their
national law, and coordinating administrative and other measures taken as appropriate to
prevent the commission of offences as set forth in article 2”.167
381. Finally, the Court held that, as the legal basis for the information transmitted
to Belgian police by United States authorities was valid, it could de facto be used by
the Belgian judicial authorities. The Court added that the analysis relating to the United
States-based e-mail addresses (or most of them) had been included in the judicial file
following a letter rogatory executed in France.168
382. The case highlights the careful consideration that needs to be given, during the
investigation phase of cases involving the use of foreign evidence, to the methods used
in the collection and transmission of such evidence. This reinforces the importance,
emphasized by several experts at the expert group meeting, of having prosecutors inte-
grated into the investigation at the earliest possible opportunity, to identify and mediate
potential evidential issues prior to trial.
383. In the Namouh case (Canada), it was necessary, at trial, for the prosecution to
produce evidence collected by an Austrian police officer; this proved problematic. Under
Austrian law, the police officer’s evidence could be admitted as evidence in the form
of a written deposition. This was not the case, however, under Canadian law, which
generally excludes hearsay evidence and requires witnesses to appear in court and give
oral testimony. In order to facilitate the production of the officer’s evidence, Canadian
prosecutors had to liaise closely with Austrian police and prosecutors to explain the
applicable rules of evidence under Canadian law, as well as with defence counsel to
facilitate an agreement that the officer’s evidence could be produced in written form.
4. The use of expert evidence
384. In terrorism-related cases, it will often be necessary for prosecutors to present
expert evidence to prove some specialized aspect or aspects of a case. The range of
potential issues that might necessitate this type of evidence is very wide, however. From
prosecutions already undertaken involving terrorist-related activity over the Internet, it
is possible to broadly identify some areas in which investigators or prosecutors might
need to give consideration to this issue.
385. The technology and communications fields continue to evolve at a rapid pace,
with increasing complexity and specialization. It is quite likely that prosecutors might
require several expert witnesses to explain different, but related, technical aspects of
computer or communications systems or related activity in the course of the same
166 United Nations, Treaty Series, vol. 2178, No. 38349.
167 Eurojust, Terrorism Conviction Monitor, Issue 8, September 2010.
168 Ibid.
117
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
proceedings, especially when there is proof that a suspect has used a particular computer,
device or Internet-related service.169
386. In addition to evidence related to computer forensics in cases involving alleged
participation in, or provision of material support to, terrorist groups, or incitement,
recruitment or training, expert evidence might be required on the ideologies, objectives
activities and organizational structures of particular terrorist groups or individuals.
387. Typically, cases involving the use of expert witnesses involves three steps or
phases: (a) clear identification of the issues (and their scope) that require an expert
opinion; (b) identification of a qualified expert; and (c) ensuring that the qualified
expert uses admissible means.170
(a) Clear identification of the issues
388. Prosecutors, working in close coordination with investigators, should at the earli-
est possible opportunity identify the issues with respect to which they consider expert
evidence will be required and engage the experts to undertake the necessary analysis,
providing clear guidance on the key elements of evidence.
(b) Identification of a qualified expert
389. When selecting expert witnesses to give expert testimony on specialized aspects
of evidence in terrorism prosecutions, prosecutors need to consider whether govern-
mental or non-governmental experts should be used. While the use of governmental
experts is permissible, and offers some advantages, this might not be desirable if pretrial
disclosure processes or defence cross-examination of such witnesses at trial is likely to
identify sensitive intelligence sources and the methods by which information supporting
their opinions has been obtained. In order to avoid this potential pitfall, prosecutors
might prefer to rely upon academic or non-governmental experts, who can base their
evidence on publicly available information that can be readily disclosed without the risk
of compromising intelligence sources or methods.171
390. A good example of a case in which non-governmental experts were engaged by
the prosecution is the Namouh case, in which two witnesses were called to explain the
goals and modi operandi of the Global Islamic Media Front (GIMF). The background
to this evidence is described in paragraph 394 below.
391. Identifying a suitable expert, particularly in highly specialized fields, can be a
significant challenge for less developed jurisdictions. Prosecutors, working with investi-
gators, should take a proactive, cautious approach, exploring all avenues to secure
(whenever possible) the necessary, suitably qualified, witness at the national level but,
when necessary, taking steps to secure a suitable witness internationally.
169Walden, Computer Crimes and Digital Investigations, p. 383.
170 National Institute of Justice, Digital Evidence in the Courtroom, chap. 3, sect. III.E.
118
171 United Nations Office on Drugs and Crime, Digest of Terrorist Cases, para. 194.
CHAPTER VI. Prosecutions
(c) Ensuring that the expert uses admissible means
392. The need for prosecution witnesses to follow and apply recognized good practice
in any examination or analysis they undertake in the particular field on which they are
being called is clearly very important. This is particularly so for any specialist forensic
analysis they undertake for the purpose of establishing the opinions they will offer as
part of the evidence that will be presented by the prosecution. Investigators and pros-
ecutors should consider, at the earliest possible opportunity, whether expert evidence
will be required on any specialized aspects of the prosecution case and, if so, should
consult and engage with suitable experts at the earliest possible point to ensure that
the evidential basis for later expert testimony is preserved in an admissible form.
393. In some cases, especially those involving computer technology, evidence can be
technically complex, and prosecutors and expert witnesses need to consider innovative
ways of presenting such evidence to judges, juries or other fact finders at trial in a
manner that is clear, easily understood and compelling. For example, the visual depic-
tion of system design or data traffic, rather than oral testimony alone, might help fact
finders to better understand technical aspects connected with computer or communica-
tion systems. Clearly, it is also important that the prosecutor have a sound working
knowledge of the particular subject area so that he or she can present terms and con-
cepts to the judge, jury or tribunal and effectively present the prosecution case.
394. The Canadian case of Namouh involved the extensive use of expert evidence
(provided by an Royal Canadian Mounted Police expert on digital forensics) on digital
evidence issues. These centred on the defendant’s alleged use of a computer (seized
from his home), and related Internet use, when participating in online discussion forums,
uploading material onto websites and communicating with another accomplice located
in Austria. This detailed expert evidence on digital forensic issues was necessary to
satisfy the court that it was the accused who had operated the computers from which
incriminating messages were sent, as well as to describe the ideologies and methods of
GIMF, the global group in which the accused was an active participant.
395. Part of Namouh’s defence focused on undermining this aspect of the prosecution
case. It was asserted that, owing to the fundamental fallibility of the Internet, it could
not be reliably used as a source of information for the expert witnesses to opine on
the activity of GIMF and other terrorist groups. In particular, the defence asserted that
the expert witnesses could not reliably ascertain whether postings on Internet chat
forums, and other forms of electronic communications, were in fact authored by alleged
terrorists or, in the alternative, were attributable to agents of the State, acting as agent
provocateurs. In this case, an expert for the prosecution offered testimony sufficient to
satisfy the court of the reliability of the methods and Internet-based materials relied
upon, and to assign the corresponding weight to the expert testimony.
396. It is noteworthy that these electronic communications took place in Arabic and
had been translated into French, with the translation in French being filed in court by
the prosecution along with the original transcript in Arabic. This aspect of the case also
highlights the care that is required when authorities seek to produce, as evidence,
119
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
translations of conversations or documents, including transcripts of intercepted com-
munications, in other languages.
397. In addition to expert testimony on critical digital evidence, the prosecution called
expert evidence on the activities and goals of GIMF; its methods of coordinating and
recruiting new members, propagating radical ideology and conducting military training;
and the methods by which it communicated via the Internet. In fact, the prosecution
produced written reports of two experts on these issues, with one of the experts testify-
ing in court to support the report conclusions. The expert from Canada at the expert
group meeting, emphasized the importance of prosecutors having more than one poten-
tial expert witness on key evidential issues, both in terms of corroborative effect and
as a contingency plan.
398. The value of this type of expert evidence in prosecutions involving charges related
to support for a terrorist organization is illustrated in the following statement by the
trial judge, referring to the “real actions counselled by the GIMF”, which was the
subject of this expert prosecution testimony:
Counsel for the defence invites the Court to regard the various messages circulated
by the GIMF as being used figuratively. The Court has no doubt on this point.
The context of these messages clearly refers to real actions counselled by the GIMF.
Death and destruction are everywhere. The jihad that GIMF promotes is violent.
[emphasis added] This promotion clearly constitutes counselling and sometimes a
threat of terrorist activities. As a result, this activity clearly falls within the defini-
tion of terrorist activity under section 83.01 [of the] Criminal Code.172
H. Other issues
1. The need for contingency planning and continuity
399. The complexity of terrorism-related prosecutions, particularly those involving
international cooperation or highly technical elements, make it highly desirable that a
team of prosecutors conduct cases, and that each be familiar with and, if necessary,
competent to continue the proceedings in the event any member of the team is unex-
pectedly unavailable to continue with the case. This precaution will ensure that the
proceedings are conducted to a high standard and minimize the likelihood of an unsuc-
cessful outcome. The cases of Namouh (Canada) and Gelowicz, Yilmaz, Schneider and
Selek (Germany) are two useful examples of large, complex prosecutions that required
a team approach, with at least one prosecutor being involved throughout the case. In
the case from Germany it is noted that the original estimate of the trial’s duration was
two years. The actual duration was much shorter, owing to guilty pleas by the defend-
ants, but even then the trial itself took three months.
120
172 Justice C. Leblond, 1 October 2009.
CHAPTER VI. Prosecutions
2. The need for enhanced training and capacity
400. In order to ensure an integrated rule-of-law approach and to preserve the integrity
of criminal justice responses to terrorism, countries need to have robust and ongoing
processes to strengthen the capacity of prosecutors to implement national counter-
terrorism legislation and related international cooperation obligations. The nature of
counter-terrorism legislation and investigations and the speed, complexities and cross-
border nature of Internet-related activity mean investigative teams, including prosecu-
tors, need to make many decisions regarding different aspects of the case within tight
time constraints. It is important that they be adequately trained and competent to
discharge their core functions in terrorism cases.
401. In countries where the risk of terrorist activity is high and institutional capacity
within prosecution services and other criminal justice agencies is low, a high priority
should be placed on developing specialist capacity within these agencies, both in terms
of prosecuting cases and with respect to related international cooperation
mechanisms.
121
VII. Private sector cooperationVII.
A. The role of private sector stakeholders
402. While the responsibility for countering the use of the Internet for terrorist pur-
poses ultimately lies with member States, the cooperation of key private sector stake-
holders is crucial to effective execution. Network infrastructure for Internet services is
often owned, in whole or in part, by private entities. Similarly, private companies typi-
cally own the social media platforms that facilitate the dissemination of user-generated
content to a broad audience, as well as popular Internet search engines, which filter
content based on user-provided criteria.
403. The effectiveness of the Internet as a medium for disseminating content related
to acts of terrorism is dependent on both the originator of the communication and its
audience having access to Internet technologies. As such, the primary approaches to
limiting the impact of such communications are by controlling access to the network
infrastructure, by censoring Internet content or a combination of both.173 While the
level of government regulation of the Internet varies greatly among member States, in
the absence of a global, centralized authority responsible for Internet regulation, private
stakeholders such as service providers, websites hosting user-generated content and
Internet search engines continue to play an important role in controlling the availability
of terrorism-related content disseminated via the Internet. Self-regulation by these pri-
vate sector stakeholders may also assist in countering terrorist communication, incite-
ment, radicalization and training activities conducted by means of the Internet. Private
monitoring services also play a role in timely identification of Internet activity which
may promote acts of terrorism.
1. Internet service providers
404. In many Member States, user access to the Internet is controlled by non-State
actors, such as private sector telecommunications providers, which own or manage the
network infrastructure. These service providers may be well placed to assist in the col-
lection of communications data or to disclose such data, as may be appropriate,174 in
furtherance of a specific investigation by law enforcement, criminal justice and intelli-
gence agencies into potential terrorist activity. Communications data held by ISPs may
constitute key evidence against perpetrators of Internet-related crime, or may provide
links to additional evidence or collaborators relevant to the investigation.
173 Conway, “Terrorism and Internet governance: core issues”, p. 26.
174 Subject to applicable safeguards and privacy regulations.
123
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
405. For example, ISPs may require users to provide identifying information prior to
accessing Internet content and services. The collection and preservation of identifying
information associated with Internet data, and the disclosure of such information, sub-
ject to the appropriate safeguards, could significantly assist investigative and prosecu
torial proceedings. In particular, requiring registration for the use of Wi-Fi networks or
cybercafes could provide an important data source for criminal investigations. While
some countries, such as Egypt, have implemented legislation requiring ISPs to identify
users before allowing them Internet access, similar measures may be undertaken by
ISPs on a voluntary basis.
(a) Cooperation with Government authorities
406. Given the sensitivities associated with terrorist-related cases, private sector stake-
holders may be incentivized to cooperate with law enforcement authorities by the posi-
tive reputational impact of such cooperation, when appropriately balanced with due
care to respect fundamental human rights, such as freedom of expression, respect for
private life, home and correspondence, and the right to data protection. The avoidance
of detrimental consequences arising out of a failure to cooperate may also be a moti-
vating factor. For example, ISPs may cooperate out of concern regarding the possible
negative connotations of being associated with supporting terrorist activity. Liability
concerns associated with hosting certain types of Internet content may also influence
the level of cooperation from private sector entities.
407. The Egyptian expert indicated that the national experience of Egypt reflected a
cooperative response by relevant private sector stakeholders to reasonable requests from
governmental authorities for the disruption of access to terrorism-related Internet con-
tent. Additionally, ISPs in Egypt were reportedly motivated to collaborate, in part, by
the recognition of the alignment of the interests of the ISPs, which could themselves
be the subject of a terrorist attack, and governmental authorities, which sought to pre-
vent and prosecute such acts of terrorism.
408. While private sector actors may demonstrate a willingness to voluntarily remove
unlawful content, they may also be compelled to do so pursuant to domestic legislation.
For example, in the United Kingdom, section 3 of the Terrorism Act 2006 provides
for “take-down” notices, which may be issued to ISPs by law enforcement authorities
(see para. 172 ff above). Take-down notices are used to advise those hosting content
that such material is deemed to be unlawfully terrorism-related, in the opinion of the
law enforcement official. ISPs that have been issued a take-down notice are required
to remove the terrorist-related content within two working days. While other jurisdic-
tions also employ take-down notices for certain offences, this is more commonly applied
in connection with cases of copyright infringement or sexually explicit content.
409. The State of Israel highlighted its successes in relation to the cooperation of
foreign private sector representatives in Israel. For example, in several investigations
involving computer crimes, requests were made to representatives of Microsoft and
Google in Israel. Upon receipt of a duly served court order, information requested by
124
the investigative authorities was immediately provided. In some cases in which it was
CHAPTER VII. Private sector cooperation
necessary to address requests to private sector representatives based in the United States,
the formal process of requesting legal assistance via governmental authorities was typi-
cally employed, with occasional resort being successfully made to direct requests to
foreign private sector corporations for identification data.
(b) Data retention
410. Several Member States have recently introduced, or proposed the introduction
of, legislation requiring telecommunications service providers to routinely capture and
archive communications data relating to their users. In 2006, driven in part by the
terrorist attacks in Madrid in 2004 and in London in 2005,175 the European Union
enacted a directive on the mandatory retention of communications traffic data (directive
2006/24/EC of the European Parliament and of the Council of the European Union
of 15 March 2006 on the retention of data generated or processed in connection with
the provision of publicly available electronic communications services or of public com-
munications networks and amending directive 2002/58/EC).176 Directive 2006/24/EC
acknowledges the challenges posed by legal and technical differences between national
provisions concerning the types of data to be retained, and the conditions and periods
of data retention.177 The directive therefore seeks to harmonize the minimum data
retention obligations of electronic communications service providers operating in Euro-
pean Union member States for the purpose of prevention, investigation, detection and
prosecution of criminal offences.
411. Directive 2006/24/EC obliges member States to adopt legislation178 requiring
telecommunications providers to retain certain traffic data related to electronic com-
munications179 for a period of between six months and two years. This traffic data
includes the information necessary to identify the originator and the recipient of Internet
mail and telephony communications, together with information on the time, date and
duration of those communications, but does not extend to the content of electronic
communications.180 Such data must be made available in connection with the investiga-
tion, detection and prosecution of serious crime to the national law enforcement authori-
ties and, through the national authorities,181 to their counterparts in other European
Union member States, in accordance with the requirements of their respective national
laws.
175 European Commission, “Report from the Commission to the Council and the European Parliament: evaluation
report on the Data Retention Directive (Directive 2006/24/EC)”, document COM(2011) 225 (Brussels, 18 April 2011),
sect. 3.2.
176 Official Journal of the European Union, L 105, 13 April 2006.
177 Ibid., preamble, para. 6.
178As at April 2011, enacting legislation was in force in 22 European Union member States.
179This includes data generated or processed by service providers in the course of their activities, such as for the
purpose of transmitting a communication, billing, interconnection, payments, marketing and certain other value-added
services.
180 Official Journal of the European Union, L 105, 13 April 2006, art. 5.
181 Ibid., art. 4.
125
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
412. For example, once transposed into domestic legislation, and subject to applicable
procedural requirements, national law enforcement authorities may request access to
data from service providers to identify subscribers using a specific IP address and those
with whom that individual has been in contact over a given period of time.182 Further,
investigations of terrorist acts may rely on data retained by service providers which
reflects the length of time taken to plan the act to identify patterns of criminal behav-
iour and relations between accomplices to the act and to establish criminal intent.183
Some European Union member States184 have indicated that data retention records are
the sole means of investigating certain crimes involving communication over the Inter-
net, such as chat room postings, which are traceable only through Internet traffic data.185
Several European Union member States186 have also reported using data retained by
service providers to clear persons suspected of crimes without having to resort to other,
more intrusive, methods of surveillance such as interception and house searches. Loca-
tion data is also important when used by law enforcement to exclude suspects from
crime scenes and to verify alibis. Data retained pursuant to enacting legislation also
enables the construction of trails of evidence leading up to an act of terrorism, includ-
ing by facilitating the identification or corroboration of other forms of evidence on the
activities and links between suspects.187
2. Websites and other platforms hosting user-generated content
413. Terrorist-related content hosted on popular websites containing user-generated
content has the potential to reach a significantly broader audience than content on
traditional specialized websites, bulletin boards and web forums, which generally appeal
to a self-selected group of individuals. According to the video-sharing website YouTube,
48 hours of user-generated videos are uploaded to its website every minute, resulting
in the equivalent of almost eight years of content being uploaded every day.188 Making
content available to the estimated 8 million unique YouTube users per month signifi-
cantly lowers barriers to accessing terrorist-related content. The sharp rise in popularity
of user-generated content in recent years increases the logistical difficulty of monitoring
terrorism-related content. Additionally, users of video-hosting websites may inadvert-
ently encounter terrorism-related content as a result of searching for, or viewing, more
moderate material, owing to embedded mechanisms which automatically suggest related
content.
182 European Commission, “Report from the Commission to the Council and the European Parliament: evaluation
report on the Data Retention Directive (Directive 2006/24/EC)”, sect. 5.2.
183 Ibid., sects. 3.1 and 5.2.
184 Belgium, Ireland and the United Kingdom.
185 European Commission, “Report from the Commission to the Council and the European Parliament: evaluation
report on the Data Retention Directive (Directive 2006/24/EC)”, sect. 5.4.
186 Germany, Poland, Slovenia and the United Kingdom.
187 European Commission, “Report from the Commission to the Council and the European Parliament: evaluation
report on the Data Retention Directive (Directive 2006/24/EC)”sect. 5.4.
126
188YouTube statistics available from www.youtube.com/t/press_statistics.
CHAPTER VII. Private sector cooperation
The Filiz G. case
In this German case, the defendant, Filiz G., was found guilty on charges of recruiting
members or supporters for foreign terrorist organizations (Al-Qaida, the Islamic Jihad Union
and Deutsche Taliban Mujahideen) and of providing support to those organizations.
In March 2009, the defendant joined an Internet forum and started publishing translations
into German of communiqués of terrorist organizations denouncing alleged crimes of inter-
national armed forces in Iraq and Afghanistan and calling on users to join or support jihad.
Being the spouse of an incarcerated German terrorist, Filiz G. was soon granted administrator
rights for the Internet forum. By the time of her arrest in February 2010, the defendant
had posted more than 1,000 contributions and commentaries, in both a publicly accessible
part of the Internet forum and in a closed section that was accessible only to registered
members. She opened nine video channels on the YouTube portal, and posted 101 videos
in all on those channels, including both publications by terrorist groups such as Al-Qaida
and the Islamic Jihad Union and videos she had produced herself. The defendant cooperated
very closely with M., the “media focal point” of the Islamic Jihad Union. He contacted her
via the Internet and initially asked her to translate texts with religious content from Turkish
into German. Subsequently, he gave her links to videos, which the defendant posted on
YouTube, and asked her to assist in collecting donations.
In one instance, the defendant translated material published on a Turkish-language web
page into German and published it on a German web page. The material appealed to
donors to support “families of the mujahideen in Afghanistan who are resisting the cruel
attacks of the crusading nations”. The text was accompanied by seven pictures, one show-
ing various food items and the other six showing children armed with assault rifles and
other weapons.
In addition to publishing fundraising material, the defendant was also involved in the actual
collection of funds. To preserve the anonymity of donors, she opened a post office box, to
which the donors addressed envelopes with their Internet user names containing cash (gen-
erally contributions of a few hundred euros). She then used Western Union Financial Services
to transfer the funds to an intermediary in Turkey, who forwarded it to M. in Waziristan.
The defendant also posted videos on the Internet thanking the donors (who for this purpose
were assigned nicknames linked to their Internet user names) and informing them of the
progress of the fundraising campaign.
At trial, in March 2011, the defendant admitted the charges and was sentenced to two-
and-a-half years of imprisonment. In sentencing her, the court found that she had been
fully aware that the propaganda material she was disseminating came from terrorist organi-
zations and that the funds she collected and transferred were intended to buy, in addition
to humanitarian goods, arms and munitions for those organizations. In noting that the
offences had taken place mainly over the Internet, the sentencing judge remarked:
[…] the court attributes particular weight to the significant dangerousness of the
dissemination of jihadist propaganda through the Internet. Materials once uploaded on
the Internet can practically no longer be controlled or removed from the web, as other
users can download, make use of and further disseminate them. Considering the nearly
worldwide use of this medium and the immensely high and continuously growing
number of users, the Internet constitutes a platform of ever greater importance for
terrorist groups to disseminate their aims and their propaganda and to evoke a world-
wide climate of fear of omnipresent terrorist threats. The dissemination of contributions
such as those published by the accused thus amounts to “intellectual arson”. It is
incomparably more durable in effect and therefore more dangerous than, for instance,
the dissemination of propaganda by leaflets or other printed media.
127
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
414. The United Kingdom case of R. v. Roshanara Choudhry provides an example of
a self-taught individual, Ms. Choudhry, who was radicalized to commit a violent act
exclusively through material accessed via the Internet and, in particular, by means of
video-hosting websites. Ms. Choudhry’s case drew international attention to the ease
with which the video-sharing platform containing user-generated content enabled her
to locate and view videos of extremist Islamic content, and the process by which her
conviction to execute an act of terrorism was formed through consistently viewing such
content over the course of several months.
415. In 2010, following discussions with the Governments of the United Kingdom, led
by the law-enforcement-based Counter Terrorism Internet Referral Unit, and the United
States, where the YouTube servers are located, YouTube’s parent company, Google Inc.,
voluntarily introduced a system which enabled content viewers to flag potential terrorism-
related content on the YouTube website. This mechanism represents an important tool
in proactively identifying content which may promote acts of terrorism.
416. Some websites and social media platforms also include provisions in their terms
of use that prohibit the use of their services to promote, inter alia, terrorist activities.
For example, the terms of service of Twitter,189 a real-time information network, prohibit
the use of the service for publishing direct, specific threats of violence against others
or for any unlawful purposes or in furtherance of illegal activities.190 In the event of
breach of such terms, the service provider reserves the right (although does not have
an obligation) to remove or refuse to distribute the offending content or to discontinue
service. Further, Twitter users are limited to those not barred from receiving services
under the laws of the United States or other applicable jurisdiction, thus excluding the
use of its services by designated terrorist organizations. Nevertheless, even when such
terms are in place, difficulties may arise in enforcement, owing in part to the broad
user base and resulting high volume of user-generated content to be monitored.
417. Recent news reports indicate that, in the case of copyright infringement, Google
often acts to remove illegal content or links within six hours of receiving a request to
do so, despite having been inundated with over five million requests related to such
content in 2011.191 The combination of a content-flagging mechanism and a similarly
diligent and timely response to suspected terrorism-related content would be a very
positive step forward in the fight against the use of the Internet for recruitment, radi-
calization, training and glorification of and incitement to acts of terrorism.
418. Content disseminated by terrorist organizations is often marked with trademarks
known to be associated with particular organizations.192 The monitoring and removal
189Available from https://twitter.com/tos.
191 Jenna Wortham, “A political coming of age for the tech industry”, The New York Times, 17 January 2012. Avail-
192“Jihadist use of social media: how to prevent terrorism and preserve innovation”, testimony of A. Aaron Weisburd,
Director, Society for Internet Research, before the United States House of Representatives Committee on Homeland
128
Security, Subcommittee on Counterterrorism and Intelligence, 6 December 2011.
CHAPTER VII. Private sector cooperation
of such easily identifiable content by hosting websites could offer significant gains in
countering the dissemination of unlawful terrorist propaganda. Further, the use of flag-
ging mechanisms, similar to those introduced on YouTube, as a standard feature across
other social networking media and Internet search engines may improve the likelihood
of timely removal of propaganda intended to further terrorist purposes. Increased meas-
ures to identify terrorism-related content, combined with enhanced formal and informal
information-sharing partnerships between State and private stakeholders, could signifi-
cantly assist in identifying and countering terrorist activity involving use of the
Internet.
419. Information-sharing is particularly important in the context of distinguishing
online content that may be objectionable from that which may be illegal (see discussion
in section I.B.1). For example, while the flagging system employed by YouTube may
assist in prioritizing certain content for review, it must subsequently be determined
whether such content meets the necessary threshold to be removed or blocked. Informal
dialogue between ISPs or hosting websites on the one hand, and criminal justice officials
on the other hand, may facilitate this process. To that end, relevant private sector stake-
holders may be encouraged to cooperate with law enforcement authorities by reporting
objectionable content suspected to be connected with any user affiliated with a known
terrorist organization or promoting the activities of such an organization.
3. Internet search engines
420. Internet search engines provide a bridge between Internet content and the end
user. Content excluded from such search engines has a significantly reduced audience.
Some Internet search engines, such as Google and Yahoo, voluntarily censor content
deemed to be sensitive or harmful to their interests. For example, following the 11
September 2001 attacks in the United States, many Internet search engines removed
search results relating to potential terrorist organizations.193 Policymakers and law
enforcement officials in several member States have encouraged similar voluntary initia-
tives to reduce ease of access through Internet search engines to content which may
promote violent acts. Voluntary implementation by search engines of a flagging system
for terrorist-related content, similar to that used by YouTube, may also be beneficial.
4. Monitoring services
421. Some private actors have also taken a more structured approach to countering
terrorist activity on the Internet. Monitoring services such as the United-States-based
Search for International Terrorist Entities (SITE) and Internet Haganah monitor and
collect open-source information related to terrorist organizations.194 Search for Inter
national Terrorist Entities, which operates as an intelligence-gathering service, obtains
significant revenues from fee-based subscriptions. As such, it and similar organizations
may therefore have better access to resources to enable the prompt identification and
193 Conway, “Terrorism and Internet governance: core issues”, p. 30.
194 Ibid, p. 31.
129
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
translation, where applicable, of Internet activities which may promote acts of terrorism.
Internet Haganah, by contrast, monitors Internet-based activity by Islamist extremist
groups with the aim of identifying and disrupting access to terrorist-related content.
Internet Haganah is funded in part through donations and operated primarily based
on the contributions of a network of volunteers. This monitoring service proactively
researches and identifies Internet content deemed to be terrorist-related and the cor-
responding hosting website. This information may be shared with law enforcement
authorities or the public or be used to contact the hosting website to promote the
removal or disruption of access to such content.195 While the purpose and operating
models of these monitoring services differ, the actions of both promote the rapid iden-
tification of terrorist-related content on the Internet, which may be useful for intelli-
gence, investigation and prosecution of such activity.
B. Public-private partnerships
422. There are many potential benefits from establishing public-private partnerships
with interested stakeholders in countering the use of the Internet for terrorist purposes.
Often-cited challenges to public-private cooperation in connection with cybercrime
generally are the lack of communication between law enforcement and service providers
regarding the efficient gathering of evidence, and the tension between privacy and the
need for data retention for enforcement purposes. Creating a forum for formal and
informal dialogue between counterparts from the public and private sectors could sig-
nificantly allay such concerns. In addition to the opportunities provided through regular
meetings among the partners involved, activities such as joint training programmes
could also assist in breaking down communication barriers and further enhancing trust
between participating partnership members.196
423. Significant progress has been made in establishing public-private partnerships in
security-related matters associated with potential terrorist attacks on vulnerable targets
or infrastructure, or relating to the prevention and prosecution of cybercrime generally.
The establishment of similar public-private partnerships in connection with the regula-
tion of the use of the Internet for terrorist purposes would be beneficial. An example
of a successful security-related public-private partnership is the Overseas Security Advi-
sory Council, established between the United States Department of State and American
private sector organizations operating abroad. The Council provides a forum for the
exchange of best practices and a platform for the regular and timely interchange of
information between the private sector and the Government of the United States con-
cerning developments in the overseas security environment, including in relation to
terrorism, as well as political, economic and social factors that may have an impact on
the security environment globally and on individual countries.197
195Ariana Eunjung Cha, “Watchdogs seek out the web’s bad side”, Washington Post, 25 April 2005. Available from
196 United Nations Interregional Crime and Justice Research Institute, “Public-private partnerships for the protec-
tion of vulnerable targets against terrorist attacks: review of activities and findings” (January 2009), para. 23.
130
197 Ibid., para. 9.
CHAPTER VII. Private sector cooperation
424. The Indonesia Security Incident Response Team on Internet Infrastructure pro-
vides another example of a security-focused public-private partnership initiative. It
brings together representatives from the postal and telecommunications services, the
national police, the Attorney General’s office, Bank Indonesia, the Indonesian Internet
Service Providers Association, the Indonesian Internet Café Association, the Indonesian
Credit Card Association and the Indonesian ICT Society (MASTEL). Members coop-
erate to, inter-alia, conduct monitoring, detection and early warning of threats and
disruptions to Internet-protocol-based telecommunications networks; conduct research
and development; provide simulation laboratories and training on the security of the
use of Internet-protocol-based telecommunications networks; provide consultative ser-
vices and technical assistance to strategic agencies or institutions; and serve as a coor-
dination centre for relevant agencies or institutions, both domestic and
international.198
425. In November 2006, the Global Forum for Partnerships between States and Busi-
nesses to Counter Terrorism was convened in Moscow. As a result of this forum, the
Group of Eight199 adopted the Strategy for Partnerships between States and Businesses
to Counter Terrorism,200 which promotes, inter alia, cooperation between Internet ser-
vice providers and other businesses and Government authorities to counter the misuse
of the Internet by terrorists and to prevent the facilitation of the final steps that lead
from extremism to terrorism. Pursuant to this Strategy, Governments are encouraged
to build closer voluntary national and international partnerships with Internet service
providers to tackle the use of the Internet for activities such as recruitment, training
and incitement to commit terrorist acts.
426. Other relevant public-private partnership initiatives include the Council of Europe
working group established in 2007, with participants from law enforcement, industry
and service provider associations, to address issues relating to cybercrime generally. The
aim of this initiative is to enhance cooperation between law enforcement authorities
and the private sector, with a view to tackling cybercrime more efficiently.
427. In 2010, the European Commission approved and provided funding for a project,
involving collaboration between academia, industry and law enforcement, intended to
create a network of Cybercrime Centres of Excellence for Training, Research and Edu-
cation
(2CENTRE) in Europe. That network currently provides training through
national centres of excellence located in Ireland and France. Each national centre is
founded on a partnership among representatives of law enforcement, industry and
academia, which collaborate to develop relevant training programmes and tools for use
in the fight against cybercrime (see section IV.G).
428. Public-private partnerships specifically targeting terrorist use of the Internet could
also provide a means to promote clear guidelines regarding information-sharing between
198Written submission of expert from Indonesia.
199 Unofficial forum of the heads of the following industrialized countries: Canada, France, Germany, Italy, Japan,
Russian Federation, United Kingdom and United States.
200A/61/606-S/2006/936, annex.
131
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
the private and public sector, consistent with applicable data protection regulations. A
good basis for information-sharing guidelines is provided by the Council of Europe
“Guidelines for the cooperation between law enforcement and Internet service providers
against cybercrime”.201 The focus of these guidelines is the establishment of relationships
of mutual trust and cooperation between public and private sector stakeholders as a
foundation for cooperation. The guidelines also emphasize the need to promote efficient
and cost-effective cooperation procedures. Law enforcement authorities and Internet
service providers are encouraged to engage in information exchange to strengthen their
capacity to identify and combat cybercrime through regular meetings and the sharing
of good practices and feedback. The guidelines also encourage the establishment of
formal partnerships and written procedures as a basis for longer-term relationships, to
ensure, inter alia, that appropriate protections are provided that the partnership will
not infringe upon the legal rights of industry participants or the legal powers of law
enforcement authorities.202
429. Recommended measures to be taken by law enforcement authorities pursuant to
the guidelines include:
""
Engaging in broad strategic cooperation with ISPs, including by conducting
regular technical and legal training seminars, as well as providing feedback on
investigations conducted or intelligence gathered, based on ISP-initiated reports/
complaints
""
Providing explanations and assistance to ISPs regarding investigation techniques
not directly related to the case at hand, in order to facilitate an understanding
of how ISP cooperation will result in more efficient investigations
""
Prioritizing requests for large volumes of data while avoiding unnecessary cost
and disruption of business operations.203
430. Recommended measures to be taken by Internet Service providers pursuant to
the guidelines include:
""
Cooperating to minimize the use of services for illegal purposes
""
Reporting criminal activity to law enforcement authorities
""
When possible, providing a list, upon request, of which types of data could be
made available for each service to law enforcement, upon receipt of a valid
disclosure request.204
431. Public-private partnerships may also provide a forum to promote minimum
standards for the secure retention of data by private sector stakeholders and enhance
the channels of communication for the provision of information by private sector stake-
holders regarding suspicious activities.
201 Council of Europe, Economic Crime Division, “Guidelines for the cooperation between law enforcement and
Internet service providers against cybercrime” (Strasbourg, 2 April 2008). Available from www.coe.int/t/dghl/cooperation/
economiccrime/cybercrime/documents/Reports-Presentations/567_prov-d-guidelines_provisional2_3April2008_en.pdf.
202 Ibid., paras. 10-13.
203 Ibid., paras. 17, 29, 30 and 33.
132
204 Ibid., paras. 41, 42 and 50.
VIII. ConclusionVIII.
A. Use of the Internet for terrorist purposes
432. The introductory chapters of the present document provided an overview, devel-
oped along functional lines, of the means by which the Internet is often utilized to
promote and support acts of terrorism, in particular with respect to propaganda (includ-
ing for the purposes of recruitment, radicalization and incitement to terrorism), training
and financing, planning and executing such acts. Emphasis is also placed on the oppor-
tunities offered by the Internet to prevent, detect and deter acts of terrorism. These
may include the gathering of intelligence and other activities to prevent and counter
acts of terrorism, as well as the gathering of evidence for the prosecution of such acts.
433. Counter-narratives and other strategic communications may be an effective means
of disrupting the process of radicalization to extremist ideals, which may in turn be
manifested through acts of terrorism. A demonstrated understanding of the broader
issues underpinning radicalization is also important in engaging in constructive dialogue
with potential recruits to a terrorist cause, and in promoting alternative, lawful means
to pursue legitimate political, social or religious aspirations.
434. Respect for human rights and the rule of law is an integral part of the fight
against terrorism. In particular, Member States reaffirmed those obligations in the
United Nations Global Counter-Terrorism Strategy, recognizing that “effective counter-
terrorism measures and the protection of human rights are not conflicting goals, but
complementary and mutually reinforcing”. The effective implementation of a rule-of-law
approach to countering the use of the Internet for terrorist purposes must be continu-
ally assessed during all stages of counter-terrorism initiatives, from preventive
intelligence-gathering to ensuring due process in the prosecution of suspects.
B. The international context
435. There is currently no comprehensive United Nations treaty on terrorism, nor is
there an official definition of the term “terrorism”. Nevertheless, the Member States of
the United Nations are in the process of drafting a comprehensive convention on inter-
national terrorism, which will complement the existing international legal framework
related to counter-terrorism. This framework is contained in a range of sources, includ-
ing resolutions of the General Assembly and Security Council, treaties, jurisprudence
and customary international law. Several regional and subregional instruments also offer
valuable substantive and procedural standards for criminalizing acts of terrorism which
may be perpetrated by means of the Internet.
133
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
436. Member States have resolved, pursuant to the Global Counter-Terrorism Strat-
egy, to take urgent action to prevent and combat terrorism in all its forms and mani-
festations and, in particular:
(a) To consider becoming parties without delay to the existing international con-
ventions and protocols against terrorism, and implementing them, and to
make every effort to reach an agreement on and conclude a comprehensive
convention on international terrorism;
(b) To implement all General Assembly resolutions on measures to eliminate
international terrorism, and relevant General Assembly resolutions on the
protection of human rights and fundamental freedoms while countering
terrorism;
(c) To implement all Security Council resolutions related to international terror-
ism and to cooperate fully with the counter-terrorism subsidiary bodies of
the Security Council in the fulfilment of their tasks.
C. Policy and legislative frameworks
1. Policy
437. Effective criminal justice responses to threats presented by the use of the Internet
by terrorists require Governments to develop clear national policies and laws dealing
with, inter alia: (a) the criminalization of unlawful acts carried out by terrorists over
the Internet or related services; (b) the provision of investigative powers for law enforce-
ment agencies engaged in terrorism-related investigations; (c) the regulation of Internet-
related services
(e.g. ISPs) and content control; (d) the facilitation of international
cooperation; (e) the development of specialized judicial or evidential procedures; and
(f) the maintenance of international human rights standards.
438. The broad classification of strategic approaches provided by the Counter Terror-
ism Implementation Task Force’s Working Group on Countering the Use of Internet
for Terrorist Purposes, involving the use of general cybercrime legislation, general (non-
Internet-specific) counter-terrorism legislation and Internet-specific counter-terrorism
legislation, provides a useful conceptual framework for policymakers and legislators.
Currently, few States have developed legislation specifically targeting acts carried out
by terrorists over the Internet. Most countries use general criminal laws, cybercrime,
and/or counter-terrorism legislation to criminalize and prosecute these types of crimes.
2. Legislation
439. In addition to using the Internet as part of actions in carrying out substantive
crimes (e.g. bombings), terrorists can use the Internet to carry out other support activi-
ties (e.g. disseminating propaganda or recruiting and training members). Countries have
used different approaches to criminalizing unlawful conduct associated with terrorism
134
carried out by using the Internet.
CHAPTER VIII. Conclusion
440. In its resolution 1624 (2005), the Security Council, inter alia, called upon States
to criminalize the incitement of terrorist acts. States are obliged, under the resolution
and other international instruments, to ensure that measures targeting acts inciting ter-
rorism fully conform with their international obligations under human rights law, refugee
law and humanitarian law.
441. The development and enforcement of laws criminalizing the incitement of acts
of terrorism while fully protecting human rights (e.g. the right to freedom of expres-
sion) presents an ongoing challenge for policymakers, legislators, law enforcement agen-
cies and prosecutors in all countries. Countries have adopted different approaches in
criminalizing acts of incitement of terrorism. Some countries have specifically criminal-
ized acts of incitement or glorification of terrorist acts, while others rely upon on
inchoate offences such as solicitation or conspiracy.
442. The investigation of terrorism cases involving the use of the Internet or other
related services by suspected terrorists often necessitates the use of specialized types of
investigative powers by law enforcement agencies. Most Governments have adopted
legislation that permits law enforcement agencies to undertake such activities in terror-
ism-related investigations. These investigative techniques should be properly authorized
under national laws and carried out in a manner that upholds fundamental human
rights protected under international human rights law.
443. Authorities will require the cooperation of telecommunications operators when
undertaking electronic monitoring, wiretaps and similar electronic investigative tech-
nique. It is desirable that Governments provide a clear legal basis for the obligations
on private sector parties, including the technical specifications required of their networks
and how the cost of providing such capabilities is to be met.
444. There is evidence that terrorists have used Internet cafes to carry out their activities;
however, the extent to which this is a problem is unknown. Some Governments have
imposed specific duties on operators of Internet cafes for law enforcement purposes
(including anti-terrorism) to obtain, retain and, upon request, produce to law enforcement
agencies photo identification, addresses and usage/connection data of customers. There
is some doubt about the utility of targeting such measures at Internet cafes only when
other forms of public Internet access (e.g. airports, libraries and public Wi-Fi hotspots)
offer criminals (including terrorists) the same access opportunities and are unregulated.
445. The issue of the extent to which Governments should regulate terrorism-related
content on the Internet is problematic, requiring the balancing of law enforcement and
human rights considerations (e.g. the right to freedom of expression). Approaches to
regulation of terrorism-related content vary, with some States applying strict regulatory
controls on ISPs and other related service providers, including in some cases the use
of technology to filter or block access to some content. Other States adopt a lighter
regulatory approach, relying to a greater extent on self-regulation by the information
society sector. Most ISPs, web hosting companies, file-sharing sites and social networking
sites have terms-of-service agreements that prohibit certain content; some terrorism-
related content might contravene these contractual restrictions.
135
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
D. Investigations and intelligence-gathering
446. Effective investigations relating to Internet activity rely on a combination of tradi
tional investigative methods, knowledge of the tools available to conduct illicit activity
via the Internet and the development of practices targeted to identify, apprehend and
prosecute the perpetrators of such acts. A proactive approach to investigative strategies
and supporting specialist tools that capitalize on evolving Internet resources promotes
the efficient identification of data and services likely to yield the maximum benefit to
an investigation.
447. There is a range of specialized utilities and hardware available to investigators
with the appropriate technical background. Due care should be taken, where possible,
in cases involving the acquisition of digital evidence to implement standardized data
recovery procedures to promote the retrieval of the maximum available evidence and
the preservation of the integrity of the data source and the chain of custody to ensure
its admissibility in court proceedings. Owing to the fragile nature of digital evidence,
its assessment, acquisition and examination is most effectively performed by specially
trained forensic experts.
E. International cooperation
448. Effective international cooperation is an important factor in many terrorism-related
prosecutions, including those involving some aspect of Internet use by perpetrators. States
are obliged, under many different international, regional, multilateral and bilateral
instruments related to terrorism and transnational organized crime, to establish policies
and legislative frameworks to facilitate effective international cooperation in the investigation
and prosecution of acts of terrorism or related serious organized crime. Currently, there
is no universal instrument related to cybercrime or terrorism imposing specific obligations
on States in relation to international cooperation. This is an impediment to effective
international cooperation in some terrorism-related investigations and prosecutions.
449. While formal channels of international cooperation remain vital, in practice infor-
mal channels are becoming equally as important. Regardless of the mode of cooperation,
trust between respective national authorities is a key element in effective international
cooperation in many cases. In addition to cooperation under formal treaties or similar
legal instruments, regional or subregional non-treaty-based initiatives aimed at strength-
ening law enforcement cooperation are also important. Countries with common security
interests in thematic areas might enter into collective arrangements that provide for
information exchange and intelligence sharing.
450. The existence of a national legislative framework providing for effective interna-
tional cooperation is a fundamental element of an effective framework for the facilitation
of international cooperation in the investigation and prosecution of terrorism cases.
Such legislation should incorporate into a country’s domestic law the principles espoused
in the universal instruments against terrorism relating to cooperation and relevant trans-
136
national organized crime.
CHAPTER VIII. Conclusion
451. While legislation is a fundamental component of any effective regime for inter-
national cooperation, it is not in and of itself the entire answer. The existence of a
properly resourced and proactive central authority which can facilitate mutual legal
assistance, using all available channels, is also key. The development and maintenance
of relationships of trust and confidence with foreign counterparts involved in coopera-
tion in cross-border criminal investigations is also important.
452. In addition to formal channels for cooperation, authorities need to develop and
utilize available informal channels for bilateral cooperation. Many national law enforce-
ment agencies operate a network of international liaison posts, which assist greatly with
the facilitation of international cooperation requests. There is no express reference to
the use of joint investigation teams in the universal counter-terrorism instruments;
however, this cooperation strategy is entirely consistent with the underlying principles
and spirit of the international cooperation elements of these instruments. Some coun-
tries, notably in Europe, have successfully adopted this approach to a number of ter-
rorism-related investigations.
453. Despite improvements, formal mutual legal assistance procedures in criminal cases
can still be lengthy processes, involving considerable amounts of bureaucracy. In cases
involving the preservation of Internet-related data held by ISPs in another jurisdiction, it
might be possible for authorities to cooperate with ISPs directly on an informal basis to
preserve such data for the purpose of the investigation or prosecution of a criminal offence.
In other situations, the exercise of a coercive power and judicial authorization may be
required, for example, with regard to the preservation, search and seizure of Internet-
related data for production and use as evidence in criminal proceedings.
454. Investigators and prosecutors should be fully cognizant of the potential impor-
tance of such data and the need to take steps at the earliest possible moment to preserve
it in a manner that ensures its admissibility as potential evidence in any later proceed-
ings. To the extent possible, national law enforcement agencies should develop, either
directly with ISPs or with their counterpart agencies in other countries, clear procedures,
involving both formal and informal elements, aimed at ensuring the earliest possible
retention and production of Internet-usage data required for a criminal investigation.
455. Some experts at the expert group meeting highlighted the fact that the need, on
the part of national authorities, to protect sensitive intelligence material often presents
an obstacle to information-sharing.
456. When considering investigative actions in other jurisdictions involving the collection
of digital evidence, authorities should be mindful of the sovereignty implications that such
actions might have for other States. Whenever possible, authorities considering investigative
steps relating to persons or objects located in another jurisdiction should notify and
coordinate such actions with their foreign counterparts in relevant countries.
457. Internet-related data (e.g. customer usage) will be important evidence in many
terrorism cases. In such cases, authorities should ensure that relevant data is preserved
137
for later evidential use in proceedings. In this regard, it is important to note
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
the distinction between “retention” of data (data retained by ISPs under a regulatory
obligation) and “preservation” of data (data that has been preserved on the basis of a
judicial order or authority). In many countries, ISPs are obliged by law to retain certain
types of communications-related data for a specified time period. Nevertheless, despite
some efforts (for example, at the regional level in Europe), there is no international
agreement on the type of data that should be retained by ISPs or the retention period.
As a result, internationally there is a wide variation in the specific type of data retained
by ISPs and the time period for which it is kept. This can be problematic in cases in
which authorities require communications-related data located in one country as evi-
dence in criminal proceedings being held in another country.
458. The development of a universally agreed regulatory framework imposing consist-
ent obligations on all ISPs regarding the type and duration of customer usage data to
be retained would be of considerable benefit to law enforcement and intelligence agen-
cies investigating terrorism cases. In the absence of a universally agreed framework for
data retention by ISPs, authorities should identify, at the earliest possible stage, whether
ISP data relevant to an investigation exists and where it is located, and initiate steps
at the earliest possible time to preserve it for possible use as evidence.
459. To the extent possible, authorities should establish informal relationships or
understandings with ISPs (both domestic and foreign) that might hold data relevant
for law enforcement purposes about procedures for making such data available for law
enforcement investigations. In the absence of such informal procedures, during investi
gations authorities should liaise at the earliest possible opportunity with foreign counter
parts, if necessary through formal channels and appropriate judicial authorizations,
regarding the preservation of such data.
460. From an evidential perspective, terrorism cases involving cross-border investiga-
tions add an additional layer to what might already be a complex task for investigators
and prosecutors, requiring them to ensure that the methods used to collect evidence
(potentially in one or more countries) and to produce it as evidence in a prosecution
conducted in another jurisdiction are in full accordance with the applicable laws and
principles of all relevant jurisdictions.
461. The dual criminality requirement (that the acts to which extradition and mutual
legal assistance relate constitute crimes in both States), commonly found in many multi
lateral and bilateral instruments relating to terrorism and transnational organized crime,
can present difficulties in criminal cases, including those relating to terrorism, that
involve some element of international cooperation.
462. Terrorism cases in which constituent acts forming part of a crime are carried
out over the Internet can raise complex jurisdictional issues, particularly in cases in
which a suspected offender is located in one country and uses Internet sites or services
hosted by ISPs in another to carry out constituent acts of a crime. Such cases have
involved persons resident in one country setting up and administering websites used to
138
promote jihad and other violent acts related to terrorism.
CHAPTER VIII. Conclusion
463. There are no binding rules under international law that deal with the issue of
how States should handle cases in which more than one State might assert jurisdiction
to prosecute a crime involving the same suspect. Typically, national authorities balance
or weigh relevant factors, including the degree of connectivity between various jurisdic-
tions and the alleged crime, in determining whether to assert and exercise jurisdiction
in the particular case. In cases involving competing jurisdictional claims, early and col-
laborative communication between relevant central authorities (often national prosecut-
ing agencies) is important in resolving such issues.
464. National data protection or privacy legislation can often restrict the ability of law
enforcement and intelligence agencies to share information with both national and
foreign counterparts. Striking a sensible balance between the human right to privacy
and the legitimate interest of the State to effectively investigate and prosecute crime is
an ongoing challenge for Governments and, in some cases, including those which involve
responses to terrorism, has been the subject of concern.
F. Prosecutions
465. An integral part of the universal legal framework against terrorism, the United
Nations Global Counter-Terrorism Strategy is the obligation imposed on States to deny
safe haven and bring to justice perpetrators of terrorist acts, wherever they might occur.
In addition to the existence of the necessary legislative framework, institutional capacity
within national prosecution agencies to uphold the rule of law when prosecuting
ŧerrorism-related cases, in accordance with the human rights of suspects and accused
persons under international human rights law, is an integral part of an effective criminal
justice response to terrorism.
466. Often, prosecutors are not merely involved in the prosecution phase of terrorism
cases but also play a direct role in the investigative phase, providing legal and strategic
advice on issues that will influence the outcome of any resulting prosecution. They are
likely to undertake their role as part of a multidisciplinary/multijurisdictional team. The
high level of trust, coordination and communication vital to effective cooperation at the
international level also needs to exist between national law enforcement, intelligence
and prosecuting agencies.
467. While new investigative techniques offer authorities enhanced opportunities to tar-
get terrorist activities on the Internet, they also carry legal risks to which prosecutors
need to remain vigilant. Differences in national laws related to the collection and admis-
sion of evidence mean these risks are higher when actions from which evidence has been
derived occur in a different jurisdiction from that in which the trial will be conducted.
468. In most countries, prosecutors exercise wide discretion with regard to whether
to institute criminal proceedings and the charges with which to do so. These decisions
are often taken in accordance with guidelines or codes which are designed to ensure
the fair, transparent and consistent exercise of this important discretion, and which
often apply thresholds based on evidential sufficiency and public interest.
139
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
469. The primary objective of terrorism-related investigations is public safety. In some
cases, authorities need to intervene to prevent the commission of terrorist acts before
there is sufficient evidence available to initiate a prosecution for the terrorist acts that
authorities suspect are being planned.
470. In these situations, authorities might need to rely upon other criminal offences
to provide the legal basis for their actions, including offences such as solicitation, con-
spiracy, criminal association or providing material support to terrorists, rather than
substantive crimes related to terrorist acts being planned. Other general penal provisions
related to fraud or the possession or use of unlawful articles (e.g. false identity/travel
documents, weapons) can be used to disrupt or compromise the activities of terrorist
groups before their planned attacks or activities are carried out.
471. In many terrorism cases, evidence used by the prosecution is based on intelli-
gence. The integration of intelligence activities into criminal justice systems remains a
fundamental problem for authorities in dealing with terrorism, i.e. how can authorities
protect sensitive intelligence underlying evidence while meeting obligations to ensure a
fair trial and effective defence for accused persons, including the obligation to disclose
all material parts of the prosecution case to the defence?
472. In terrorism cases involving the use of computers or the Internet, digital evidence
will be an important part of the prosecution case. The use of such evidence invariably
gives rise to issues related to admissibility. It is critical that great care be taken through-
out the investigation and prosecution of the case to ensure that the methods used for
the collection, preservation, analysis and production of digital evidence are in full con-
formity with the relevant rules of evidence or procedure and follow established good
practice
473. Prosecuting authorities will need to satisfy a court of the reliability of digital
evidence, including its methods of collection, analysis and production. The procedures
for preserving the integrity of evidence is known as the “chain of custody” or “chain
of evidence”. When such evidence is collected in one jurisdiction for use at trial in
another, the situation is considerably more complicated and requires careful attention
by investigators and prosecutors. In cases in which authorities identify the existence
and/or location of relevant digital evidence, they should explore means (informal and
formal) of obtaining and preserving it for evidential purposes. The channel chosen
should ensure the admissibility of the evidence in the country where the trial will take
place.
474. Legal principles and procedures related to the collection and admissibility of
evidence in criminal proceedings often differ between jurisdictions. A significant part
of the work of authorities in cross-border investigations involves “mediating” different
aspects of evidence. This can be a complex, time-consuming process but is a critical
factor in the success of prosecutions. Any legal deficiencies in the methods by which
evidence ultimately used at trial is collected, preserved, transmitted or produced will
140
almost certainly be challenged by the defence.
CHAPTER VIII. Conclusion
475. In terrorism cases, it will often be necessary for prosecutors to present expert
evidence to prove some specialized aspect(s). Areas in which expert testimony is often
required include the technology and communications fields and the ideologies, activities
and organizational structure of terrorist groups. It is quite possible that prosecutors
might require several expert witnesses. Typically, cases involving the use of expert wit-
nesses involve three steps or phases: (a) clear identification of the issues (and their
scope) that require an expert opinion; (b) identification of a qualified expert; and (c)
ensuring that the qualified expert uses admissible means.
476. Prosecutors should at the earliest possible opportunity identify the issues on
which expert evidence is likely to be required and engage experts to undertake the
necessary analysis, if necessary, providing clear guidance on the key rules of procedure
or evidence. When selecting expert witnesses, prosecutors need to consider whether
governmental or non-governmental experts should be used. While there are benefits to
using governmental witnesses, using non-governmental experts might be desirable in
cases in which sensitive intelligence sources or methods have been used as the basis
for their evidence. Identifying a suitable expert, particularly in highly specialized fields,
can pose a significant challenge for less-developed jurisdictions. Wherever applicable,
expert witnesses should follow and apply recognized good practice in the particular
field with respect to which they are being called. Owing to the complexity of some
expert testimony, consideration should be given to innovative ways of presenting com-
plex evidence to judges, juries or other fact-finders at trial in an easily understood way.
It is important that the prosecutor has a sound working knowledge of the particular
subject area.
477. The complexity of many terrorism-related prosecutions, particularly those
involving international cooperation or highly technical elements, make it highly desirable
that a team of prosecutors conduct cases. In order to ensure an integrated rule-of-law
approach and to preserve the integrity of criminal justice responses to terrorism,
countries need to have robust and ongoing processes to strengthen the capacity of
prosecutors to implement national counter-terrorism legislation and related international
cooperation obligations. In countries where the risk of terrorist activity is high and
institutional capacity within prosecution services and other criminal justice agencies is
low, a high priority should be placed on developing specialist capacity within these
agencies, not only in terms of prosecuting cases but also with respect to related
international cooperation mechanisms.
G. Private sector cooperation
478. While the responsibility for countering the use of the Internet for terrorist
purposes ultimately lies with Member States, the cooperation of key private sector
stakeholders is crucial to effective execution. Proactive engagement with private sector
stakeholders such as service providers, websites hosting user-generated content and
Internet search engines will continue to play an important role in controlling the
availability of terrorism-related content disseminated via the Internet.
141
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
479. The establishment of public-private partnerships in connection with the regula-
tion of the use of the Internet for terrorist purposes would be beneficial. Similar initia-
tives have been successfully developed with respect to other areas of counter-terrorism,
and to combat cybercrime generally. These initiatives provide a forum for formal and
informal dialogue between counterparts from the public and private sectors, and also
support activities such as joint training programmes which may assist in breaking down
communication barriers and further enhancing trust, understanding and the develop-
ment of harmonized practices between participating partnership members.
142
Vienna International Centre, PO Box 500, 1400 Vienna, Austria
Tel.: (+43-1) 26060-0, Fax: (+43-1) 26060-5866, www.unodc.org
United Nations publication
Printed in Austria
V.12-52159—September 2012—350
BY ORDER OF THE
AIR FORCE MANUAL 31-201, VOLUME 6
SECRETARY OF THE AIR FORCE
17 MAY 2002
Certified current 29 June 2010
Security
CIVIL DISTURBANCE
COMPLIANCE WITH THIS PUBLICATION IS MANDATORY
NOTICE: This publication is available digitally on the AFDPO WWW site at:
OPR: HQ AFSFC/SFOP
Certified by: HQ USAF/XOF
(SMSgt Walter Filipiak)
(Brig Gen James M. Shamess)
Supersedes AFMAN 31-201, Vol 3,
Pages: 98
1 December 1999
Distribution: F
This manual provides preplanning guidance for handling emergency situations, which include the full
spectrum from civil disobedience through hostile disturbances to violent acts of terrorism. It discusses the
concept of operations in planning for these crisis situations and offers an outline for preparation, execu-
tion and resolution of mass disturbances. Air National Guard units will use this manual as guidance. The
use of name or mark of any specific manufacturer, commercial product, commodity or service in this pub-
lication does not imply endorsement by the Air Force. Refer recommended changes and conflicts between
this and other publications to HQ AFSFC/SFOP, 1720 Patrick Street, Lackland AFB, TX, 78236, on the
AF Form 847, Recommendation for Change of Publication. The reporting requirement in this publica-
tion (para 11.6.1.) is exempt from licensing in accordance with AFI 33-324, The Information Collections
and Reports Management Program; Controlling Internal, Public, and Interagency Air Force Information
Collections.
SUMMARY OF REVISIONS
This document changes the title of AFMAN 31-201, Vol 3 to AFM 31-201, Vol 6. Chapter 8, para 8.6.,
was rewritten to include only information identifying what pepper spray is. All other information con-
cerning pepper spray was rewritten into AFMAN 31-222, Security Forces Use of Force Manual. It cor-
rects administrative errors, updates references and changes format. It updates the acronym and reference
listings.
Chapter 1— GENERAL
7
1.1. Introduction
7
Chapter 2— MILITARY OPERATIONS OTHER THAN WAR (MOOTW)
8
2.1. MOOTW Perspective
8
2
AFMAN31-201 17 MAY 2002
2.2. The Environment
8
2.3. MOOTW Principles
9
2.4. Missions
9
Chapter 3— CIVIL DISTURBANCES
11
3.1. Defined
11
3.2. Federal Intervention and Aid
11
3.3. Roles of the States
11
3.4. Presidential Powers
11
3.5. Causes
12
3.6. Locations
12
3.7. Role of Military Forces
13
3.8. Levels of Disturbances
14
Chapter 4— THE PARTICIPANTS
15
4.1. The Environment
15
4.2. The Human Factor
15
4.3. Impact of Social Factors on a Crowd
15
4.4. Control Force Social Factors
16
4.5. Crowd Tactics
16
Chapter 5— TRAINING AND INFORMATION
19
5.1. Civil Disturbance Training
19
5.2. Information Needs
20
5.3. Threat Analysis
21
Chapter 6— OPERATIONS
22
6.1. Restore Order
22
6.2. Isolate the Disturbance
22
6.3. Protect Targets
22
6.4. Crowd Control
22
Table 6.1. Civil Disturbance Target Security Measures
23
6.5. Establishing (Civil) Control
24
6.6. Serious Threats
25
AFMAN31-201
17 MAY 2002
3
Chapter 7— THE RIOT BATON
27
7.1.
Perspective
27
7.2.
The Riot Baton
27
Figure 7.1.
Vulnerable Body Points
28
Figure 7.2.
Fatal Impact Points
29
Figure 7.3.
Placing Baton Thong on Thumb
30
Figure 7.4.
Wrapping Thong Around Back Of Hand
30
Figure 7.5.
Completed Baton Grip
30
Figure 7.6.
Parade Rest
31
Figure 7.7.
Position Of Attention With 36” Riot Baton
32
Figure 7.8.
Port Position
33
Figure 7.9.
On-Guard Front View
34
Figure 7.10.
On-Guard Side View
35
7.3.
Offensive Techniques
35
Figure 7.11.
Straight Forward Thrust, Left Tip
36
Figure 7.12.
Straight Forward Smash Initiation
37
Figure 7.13.
Straight Forward Smash Moment of Contact
37
Figure 7.14.
Modified Smash Initiation
38
Figure 7.15.
Modified Smash Mid-Execution
38
Figure 7.16.
Modified Smash Moment of Contact
39
7.4.
Defensive Techniques
39
Figure 7.17.
Radial/Forearm Strike
40
Figure 7.18.
Radial Forearm Strike Close-Up
40
Figure 7.19.
Leg Strike
41
Figure 7.20.
Leg Strike Close-Up
41
Figure 7.21.
Calf Strike
42
Figure 7.22.
Calf Strike Close-Up
42
Figure 7.23.
Defensive Response Step Away
43
Figure 7.24.
Defensive Response Mid-Execution
44
Figure 7.25.
Defensive Response Moment of Contact
44
4
AFMAN31-201 17 MAY 2002
7.5.
Come-Along Techniques
44
Figure 7.26.
Two-Person Carry
45
Figure 7.27.
Two-Person Carry with Batons
46
Figure 7.28.
Two-Person Carry with Batons (lift)
46
Figure 7.29.
Two-Person Carry for Person Resisting
47
Figure 7.30.
Two Person Carry for Person Resisting
47
Figure 7.31.
One-Person Carry
48
Figure 7.32.
One-Person Carry with Baton
49
Figure 7.33.
One-Person Carry with Baton
49
7.6.
Come-Along Holds
50
Figure 7.34.
Riot Baton Used as a Restraint and Come-Along
50
Figure 7.35.
Riot Baton Used as a Restraint and Come-Along
51
Figure 7.36.
Gooseneck Come-Along
52
Figure 7.37.
Gooseneck Come-Along
52
Figure 7.38.
Front Hammerlock
53
Figure 7.39.
Front Hammerlock
54
Figure 7.40.
Front Hammerlock
54
Figure 7.41.
Front Hammerlock
55
Figure 7.42.
Fingers Come-Along
56
Figure 7.43.
Fingers Come-Along
56
Figure 7.44.
Groin Lift
57
Figure 7.45.
Groin Lift
57
Figure 7.46.
Baton Come-Along
58
Figure 7.47.
Baton Come-Along
59
Figure 7.48.
Baton Come-Along
59
Chapter 8— CORRESPONDING EQUIPMENT AND USE
60
8.1. Motivation
60
8.2. The Civil Disturbance Crash Helmet (Figure 8.1.)
60
Figure 8.1. Civil Disturbance Crash Helmet
60
AFMAN31-201
17 MAY 2002
5
Figure 8.2.
Civil Disturbance Crash Helmet Internal Adjustments
61
Figure 8.3.
Civil Disturbance Crash Helmet External Components
62
Figure 8.4.
Kevlar Helmet with Riot Faceshield
62
8.3.
MCU-2A/P and M17(A1/A2) Gas Masks
62
Figure 8.5.
MCU-2A/P Gas Mask Front View
64
Figure 8.6.
MCU-2A/P Gas Mask Side View
64
Figure 8.7.
M17 And MCU-2A/P Carry
65
8.4.
The Fragmentation Protective Body Armor
65
8.5.
Body Shields
66
Figure 8.8.
Use of Body Shields in a Crowd Control Formation
67
8.6.
CS Riot Control Hand Grenades
67
Figure 8.9.
ABC-M7A2 and ABC-M7A3 Riot Control Grenades
69
Figure 8.10.
ABC-M25A2 Riot Control Grenade
70
Figure 8.11.
Hand Grenade Grip (Right-handed)
70
Figure 8.12.
Hand Grenade Grip (Left-handed)
71
Figure 8.13.
Throwing the Hand Grenade From the Standing Position
72
Figure 8.14.
Throwing the Hand Grenade From the Kneeling Position
72
Figure 8.15.
Throwing the Hand Grenade From the Prone Position
73
8.7.
CAP-STUN ® Pepper Spray (NSN: 1365-01-438-5694)
73
8.8.
Non-Lethal Weapons
74
Chapter 9— FORMATIONS AND TACTICS
75
9.1. Overview
75
9.2. Crowd Control Formations
75
Figure 9.1. Crowd Control Formation Key
76
9.3. Flight Organization
77
9.4. Skirmisher’s Line (Figure 9.2.)
78
Figure 9.2. Skirmisher’s Line
80
9.5. Flight Echelon Right (Figure 9.3.)
80
Figure 9.3. Flight Echelon Right
81
9.6. Flight Echelon Left
81
6
AFMAN31-201 17 MAY 2002
Figure 9.4. Flight Echelon Left
82
9.7. Flight Wedge
82
Figure 9.5. Flight Wedge
83
9.8. Flight Response to Riot Control Agents
83
Figure 9.6. Formation Hand and Arm Signals
84
Figure 9.7. Flight Initial Response to Gas
84
Figure 9.8. Control Force Member Initial Response to Gas
85
Figure 9.9. Control Force Member Donning M17 Gas Mask
85
Figure 9.10. Control Force Member Prepared for Chemical Dispersions
86
Figure 9.11. Skirmisher’s Line Prepared for Chemical Dispersions—Quick Reaction Complete
86
9.9. Sniper Fire Immediate Actions
86
Figure 9.12. Flight Countersniper Reaction
87
Chapter 10— MILITARY WORKING DOG EMPLOYMENT
88
10.1. Prologue
88
10.2. MWD Types And Characteristics
88
Table 10.1. Attributes of Military Working Dogs
89
10.3. Civil Disturbance Operations
89
10.4. Tracking Ability
89
10.5. Riots and Crowd Control
89
Chapter 11— COMMAND AND SUPPORT FUNCTIONS
91
11.1. Leadership
91
11.2. Span Of Control
91
11.3. Rules Of Engagement
91
11.4. The Mobile Support Force (MSF)
92
11.5. Logistics
92
11.6. Processing Actions
93
11.7. Medical Services
95
11.8. Media Relations
95
Attachment 1— GLOSSARY OF REFERENCES AND SUPPORTING INFORMATION
97
AFMAN31-201
17 MAY 2002
7
Chapter 1
GENERAL
1.1. Introduction. Civil disturbances present unique challenges to the armed forces. The roles and mis-
sions of the armed forces inherently make the Department of Defense (DoD) a likely target for civil dis-
turbances both at home and abroad. The disturbances may range from peaceful demonstrations and rallies
outside a main gate to full scale riots that include burning and looting government property inside the
perimeter fence. The information, technology and weapon systems entrusted to our care require absolute
protection. The challenge arises in dealing with civil disturbance situations. Attempting to understand,
predict and control crowd behavior is a highly technical field that requires specialized training. Compli-
cating this challenge is the fact that most of the specialized training is not common to any of our everyday
missions and is extremely perishable, which is the focus of this manual. Key objectives of this manual
include:
1.1.1. Providing basic guidance from a number of current references (Attachment 1). This manual
uses many references from Army Field Manual (FM) 19-15, Civil Disturbances.
1.1.2. Providing guidance that will be most beneficial when applied in a just-in-time training environ-
ment.
1.1.3. Providing a generic how-to guide that will require detailed development and coordination with
other base or deploying agencies--consider all S-functions.
1.1.4. Tailoring specific response actions based on the local situation.
1.1.5. Recognizing perishable skills, coupled with the out-of-mission role that can complicate an
already challenging operation that demands precise and intense training prior to any deployment.
1.1.6. Dealing with civil disturbance situations is uncommon for most security forces personnel. To
provide a frame of reference, we first need to look at what has become known as military operations
other than war (MOOTW). This originated from the end of the Cold War, which precipitated radical
changes in the types and frequency of missions DoD has undertaken.
8
AFMAN31-201 17 MAY 2002
Chapter 2
MILITARY OPERATIONS OTHER THAN WAR (MOOTW)
2.1. MOOTW Perspective. The US Army FM 100-5, Operations, Chapter 13, describes in considerable
detail the concept and evolving history of MOOTW. This chapter shall model that reference in condensed
format with Air Force terminology applied. It is within this framework that this manual shall approach
civil disturbances, corresponding environmental factors and response tactics.
2.2. The Environment. The Air Force’s primary mission is to fly, fight and win our nation’s wars.
Throughout history, the Air Force has also been called on to support national interests in operations other
than war (e.g., the Berlin Airlift, allied support during the Falklands war, Hurricane Andrew disaster
relief). Army FM 100-5 makes an excellent qualifying statement in that MOOTW is not new to our armed
forces. However, the “pace, frequency and variety” have considerably increased over the last three
decades. Key tenets include:
2.2.1. Military operations other than war often are of long duration and undergo a number of shifts in
direction during their course. Immediate solutions to difficult problems may not be obvious or may
jeopardize long-term objectives. Peacekeeping, for example, demands that the peacekeeping force
maintain strict neutrality. One or more belligerents may attempt to provoke a response from peace-
keeping forces that could undermine long-term peacekeeping efforts. United Nations (UN) troops
being held, as hostages in Bosnia-Herzegovina are an excellent example of MOOTW shift.
2.2.2. In military operations other than war, victory comes more subtly than in war. Disciplined
forces, measured responses and patience are essential to successful outcomes.
2.2.3. Military operations other than war may precede and/or follow war or occur simultaneously
with war in the same theater. These operations may occur in the United States or on foreign soil. The
operational design promotes regional stability, maintains or achieves democratic end states, retains
US influence and access abroad, provides humane assistance to distressed areas, protects US interests
and assists US civil authorities.
2.2.4. Such operations are often joint in nature and may involve numerous US and foreign govern-
ment agencies:
2.2.4.1. US State Department--very often the lead agency with the ambassador serving as the key
individual.
2.2.4.2. UN--becoming much more involved as the lead agency.
2.2.4.3. Department of Justice--particularly in areas of counternarcotic operations.
2.2.4.4. Agency for International Development.
2.2.4.5. Federal Emergency Management Agency--lead agency for natural disasters.
2.2.4.6. American and International Red Cross.
2.2.4.7. Central Intelligence Agency.
2.2.4.8. Department of Agriculture.
AFMAN31-201
17 MAY 2002
9
2.2.5. Peacetime operations rely heavily on cultural orientations and regional expertise. Often a
diverse group of forces or agencies integrate to achieve a specific objective.
2.2.6. MOOTW will not always be peaceful. While everyone has an intrinsic right of self-defense, the
use of overwhelming military force may complicate the process toward the end objective. As such,
field commanders may find themselves operating under strict rules of engagement (ROE).
2.2.7. The armed forces ability to operate in crisis environments under extreme conditions may give
it the de facto lead in operations normally conducted by other (nonmilitary) agencies. Air Force com-
manders must remain sensitive to outward perceptions and properly subordinate their forces to the
agency in charge.
2.3. MOOTW Principles. DoD bases warfighting doctrine on well-established principles of war. Mili-
tary operations other than war also have principles to guide our actions. MOOTW that involve our forces
in direct combat incorporate the principles of war. Other operations may require modification to certain
principles. REMINDER: These principles are guides for action, not fixed requirements.
2.3.1. Objective. Direct every military operation toward a clearly defined, decisive and attainable
objective.
2.3.2. Unity of Effort. Seek unity of effort toward every objective; seek an atmosphere of cooperation.
2.3.3. Legitimacy. Sustain the lawfulness of the operation and host government. Actions must demon-
strate the constituted authority is genuine, effective and one that employs appropriate means for rea-
sonable purposes.
2.3.4. Perseverance. Prepare for the measured, protracted application of military capability in support
of strategic aims.
2.3.5. Restraint. Apply appropriate military capability prudently; disciplined application of force
using established ROEs.
2.3.6. Security. Never permit hostile factions to acquire an advantage.
2.4. Missions. MOOTW typically include, but are not limited to, the following (Note: Not all of these
missions require use of force):
2.4.1. Noncombatant Evacuation Operations (NEO). NEOs relocate endangered civilian noncomba-
tants. These operations may involve US citizens or host nation personnel. NEOs occur in a peaceful,
orderly fashion (but may require force).
2.4.2. Arms Control. Select units monitor the proliferation of weapons and associated technology,
verify status of arms agreements and demilitarize munitions and hardware.
2.4.3. Security Assistance. Through security assistance programs, the US provides defense material,
military training and defense-related services (e.g., grant, loan, credit or cash sales) to further our
national objectives.
2.4.4. Nation Assistance. This type of assistance supports a host nation’s efforts to promote develop-
ment--primarily through host nation resources. In UN terms, nation assistance equates to
“peace-building operations.” These operations seek to promote long-term stability, develop demo-
cratic institutions, develop infrastructures, initiate strong free-market economies and provide an envi-
10
AFMAN31-201 17 MAY 2002
ronment allowing for orderly political change and economic progress. Education and transfer of skills
to the host nation are essential for this type of mission to succeed.
2.4.5. Counterdrug Support. Armed forces support federal, state, local and foreign government law
enforcement agencies to interdict the flow of illegal drugs at the source, in transit and during distribu-
tion.
2.4.6. Combating Terrorism. The Department of State is the lead agency in combating terrorism over-
seas or on the high seas. The Department of Justice (Federal Bureau of Investigation) has responsibil-
ity within the US. The Department of Transportation, Federal Aviation Administration, fights
terrorism on aircraft in flight within the territories of the US. The Department of Defense supports
each of these agencies in their respective roles.
2.4.7. Military alternatives include:
2.4.7.1. Peacekeeping Operations--support diplomatic efforts to maintain peace in potential con-
flict areas.
2.4.7.2. Peace Enforcement--normally military intervention to restore peacekeeping operations.
2.4.7.3. Show of Force--demonstrates US resolve to diffuse situations detrimental to US objec-
tives.
2.4.7.4. Insurgent/Counterinsurgent Support--military instrument of national power (administra-
tive, logistical and operational training) supports political, economic and informational objectives.
2.4.7.5. Attacks and Raids--damage or destroy high-value targets to demonstrate US capability
and/or resolve.
2.4.8. Humanitarian Assistance/Disaster Relief. These operations fall within the overall context of
humanitarian assistance. The military, during emergency situations--natural or man-made--works to
prevent loss of life and/or property. The armed forces can provide logistics to move supplies, extract
victims, establish emergency communications, conduct medical support and render emergency repairs
to vital facilities. The armed forces may also provide personnel for civil relief or help civil authorities
to restore and maintain public safety.
2.4.9. Support To Domestic Civil Authorities. This tasking encompasses domestic:
2.4.9.1. Disaster relief.
2.4.9.2. Humanitarian assistance.
2.4.9.3. Civil disturbance suppression.
AFMAN31-201
17 MAY 2002
11
Chapter 3
CIVIL DISTURBANCES
3.1. Defined. Civil disturbances arise from acts of civil disobedience. These acts occur most often when
participants in mass acts of civil disobedience become antagonistic towards authority and authorities must
struggle to take the initiative from an unruly crowd. In the extreme, civil disturbances include acts of
criminal terrorism. Civil disturbances, in any form, are prejudicial to public law and order. The com-
mander is responsible for maintaining law and order on the military installation. Commanders respond to
disturbances using installation resources. Violence and disorder by any individual or group of individuals
will not be tolerated. Commanders must be prepared to counter a disorder if preventative measures fail.
This preparation should consist of the following elements:
3.1.1. Know the statutory and directive authority on which control actions rest.
3.1.2. Maintain accurate intelligence.
3.1.3. Ensure all personnel assigned civil disturbance related tasks are adequately trained.
3.1.4. Ensure personnel are properly equipped to handle civil disturbances.
3.1.5. Develop plans that are flexible enough to ensure available manpower and equipment is used to
the best advantage when violence occurs.
3.2. Federal Intervention and Aid. The US Constitution and US Code (USC) empower the President to
direct federal intervention in civil disturbances to:
3.2.1. Respond to state requests for aid in restoring order.
3.2.2. Enforce the laws of the United States.
3.2.3. Protect the civil rights of citizens.
3.2.4. Protect federal property and functions.
3.3. Roles of the States. Under the Constitution, each state is responsible for protecting life and property
within its boundaries. State and local governments use their civil forces to maintain law and order and
quell civil disturbances.
3.4. Presidential Powers. The Constitution and federal statutes authorize the President to direct the use
of armed federal troops within the 50 states, District of Columbia, Puerto Rico and US possessions and
territories and their political subdivisions. The President also has the power to federalize the National
Guard of any state to suppress rebellion and enforce laws.
3.4.1. Law. The President can also employ federal troops to ensure the execution of US law when a
state opposes or obstructs US law or impedes the course of justice under those laws. The President can
employ armed federal troops to suppress insurrection, domestic violence, unlawful assemblies and
conspiracy. The key is, if such acts deprive the people of their constitutional rights or privileges and a
state’s civil authorities cannot or will not provide adequate protection, then employment of federal
troops is authorized.
12
AFMAN31-201 17 MAY 2002
3.4.2. Property. The President may also choose to use armed federal troops to protect federal property
and functions when the need for protection exists and local civil authorities cannot or will not give
adequate protection. The US has a right to protect all federal property and functions regardless of their
location.
3.4.3. Limits. While federal law authorizes domestic use of military force to suppress violence or
insurrection, the Constitution and federal law provide certain restrictions. Under the Posse Comitatus
Act neither active nor reserve personnel (USC, Title 10) may execute the law in place of duly
appointed law enforcement officials without specific presidential or congressional approval and direc-
tion. The Posse Comitatus Act does not apply to the National Guard (USC, Title 32) until those airmen
have been federalized.
3.5. Causes. Civil disturbances may arise from a number of causes. Most often they arise from political
grievances, social unrest, terrorist acts or foreign influences. A single cause may trigger the event or it
may arise from a combination of causes.
3.5.1. Political Grievances. Demonstrations of political grievances range from simple protests on spe-
cific issues to full-scale civil disobedience. Many forms of political protest, while disruptive, are not
unlawful. These protests may be spontaneous, but most often are planned events. Often political pro-
testers coordinate with local authorities. Most protesters are law-abiding citizens and intend for their
protests to be nonviolent. Violence occurs mainly when control forces must try to contain a protest or
arrest protesters involved in civil disobedience. The presence of agitators increases the chance of vio-
lence. Agitators want to provoke the control force into overreacting, which will embarrass the author-
ities. Violence and overreaction by the control force can also gain media and public sympathy for the
protesters.
3.5.2. Social Unrest. Urban conflicts and community unrest arise from highly emotional socio-eco-
nomic issues. Economically deprived inner-city residents may perceive themselves as being treated
unjustly or ignored by the people in power. When tension is high, it takes only a minor incident or a
rumor of an injustice to ignite a civil disturbance. This is particularly true if community relations with
the local police are part of the problem.
3.5.3. Terrorist Acts/Foreign Influences. Many disaffected groups seek to embarrass the government.
Disturbances may be a cover for terrorism. Often an overriding goal is to cause an overreaction by
authorities with the intent to gain sympathy from the general population. Foreign nations may employ
surrogates. These surrogates create activities that promote the sponsor-state’s interests. Agents of the
foreign nations may be part of the disturbances and can be in key leadership positions. If the agents
can get the targeted government to overreact, then the repression serves to further expand support for
the foreign influence.
3.6. Locations. Civil disturbances usually occur at places symbolic of a grievance, near the cause of the
grievance or close at hand to an aggrieved crowd. Examples of such places are nuclear weapons facilities
or power plants, in urban areas, at refugee camps or at government facilities. Nuclear weapons facilities
and power plants are subject to demonstrations by anti-nuclear activists. These activists demonstrate at
places they know or believe develop, build, transport or store nuclear weapons, weapons-grade (nuclear)
material or their components.
3.6.1. Government Facilities. US government facilities such as recruiting offices, federally leased
buildings, Reserve Officer Training Corps (ROTC) buildings and federal courthouses can also be the
AFMAN31-201
17 MAY 2002
13
targets of demonstrations. A group may target a government facility simply because they attach a
symbolic value to it or perceive a connection between it and the policy they are protesting. This is
especially true of anti-war and anti-nuclear protest groups. They may choose a facility because they
see it as the source of their grievance. Likewise, they may target a facility because people working
there are seen as having the power to address the group’s grievance.
3.6.2. Refugee Camps. Refugee and resettlement camps can become the focus of a civil disturbance.
Large numbers of refugees attempting to enter the US in mass are often placed temporarily in refugee
camps until they can be resettled. These camps can either be in the US, a US-controlled area like
Guantanamo Bay or in friendly allied nations. Regardless of the location, resettlement can be a slow
and difficult process. The boredom, frustration and uncertainty refugees experience in these camps
can create tensions that may erupt into violence. Agitators may infiltrate refugee camps to exploit
these tensions in ways to embarrass and/or force the US into action.
3.6.3. Other Demonstration Sites. Demonstrations at US government facilities are not limited to those
in the US. US facilities in foreign nations can be locations of civil disturbances. DoD installations, US
embassies and US consulates in foreign nations are favorite targets of demonstrators. DoD installa-
tions in foreign nations are often scenes of protest against US foreign policy. The actual installation
and its mission may or may not be the true target. Often the installation is just a highly visible symbol
of the US government.
3.7. Role of Military Forces. The preservation of law and order in the civilian community is the respon-
sibility of state and local governments and law enforcement authorities. The preservation of law and order
on the federal property of a military installation is the responsibility of the installation commander and
military law enforcement authorities.
3.7.1. Scope. Within the Air Force, the security forces act as the primary control force for civil distur-
bances that occur on Air Force installations. Under certain circumstances, and if called upon by com-
petent authority, security forces may also act as the control force for civil disturbances that occur in
the local community. Additionally, security forces may act as the control forces for any migrant or ref-
ugee operations when directed by command authorities. Requests for military support to civilian law
enforcement officials in connection with civil disturbances will be addressed in accordance with AFI
10-802, Military Support to Civil Authorities, DoDD 3025.12, Military Assistance for Civil Distur-
bances, and DoDD 3025.15, Military Assistance to Civil Authorities.
3.7.2. Responsibilities. Regardless of the nature of the disturbance, security forces members must dis-
play fair and impartial treatment during all contacts with the civilian population and any other partic-
ipants in any civil disturbance. In all cases, personnel must adhere to the principle of minimum force
as outlined in AFI 31-207, Arming and Use of Force by Air Force Personnel. Whenever possible,
have civil police apprehend, process and detain civil law violators. Security forces perform these func-
tions only when necessary and only to the minimum extent required. Return these functions to civil
authorities as soon as possible. As the disturbance subsides, the commander should take steps to
restore control to civil authorities. The control force gradually reduces the number and scope of its
operations and should begin removing equipment from the area. Caution is required. Past experience
has shown that rapid and complete withdrawal of military forces creates a dangerous vacuum. The
vacuum often causes the disturbance to flare up since protesters believe civil authorities cannot main-
tain control. The security forces goal should be a phased return of control to civil authorities.
14
AFMAN31-201 17 MAY 2002
3.8. Levels of Disturbances. In most cases, crowd behavior escalates through many stages before vio-
lence erupts. When personnel can recognize key aspects of each stage, they have the best chance to con-
trol or disperse the crowd before it gets violent. The most recognizable stages are listed below with
essential components of each stage identified.
3.8.1. Periods of Increased Tension. There are many indications that a base or community is in a
period of increased tension as far as human relations go. Identifiers marking this phase may appear as
increased polarization in living, dining and work areas. Graffiti on walls or overheard conversations
may indicate periods of increased tension. The biggest mistake at this stage is an overreaction to these
situations by civil or military authorities. Block watch or community meetings are solid avenues to
reduce tensions, air grievances and establish understanding.
3.8.2. Scattered Minor Incidents of Violence. This phase may include incidents of harassment
between individual members of opposing groups. Increase first-line supervision and community
policing in high-incident areas to avoid escalation.
3.8.3. Group-Oriented Violence. Roaming, unorganized groups bent on either destruction of property
or assaults on people begin to show up with greater frequency and in larger groups. Leaders of these
groups intentionally defy orders and authority. This is the first level of actual disturbance requiring
direct police action. Riot control forces should assemble early in this phase, deploy to the scene and
employ necessary measures (including force) to maintain order. Attempt to isolate and/or apprehend
leaders and agitators. Use command action to stabilize the situation without force, if possible.
3.8.4. Full Riot Phase. Riots include widespread destruction of property, total defiance of authority,
open mob action and serious breaches of the peace. This level could result in serious injury or death to
innocent persons. At this time, a full civil disturbance operation should already be in force and the
mission becomes one of mob dispersal and restoration of order as rapidly as possible. It is best to
apprehend individuals after the mob is broken into small groups.
3.8.5. Summary. These levels of confrontation do not necessarily occur in order. Any phase could
occur at any time and more than one phase could occur at the same time at different locations on the
base or in the local community. A peaceful, orderly demonstration outside one gate could occur while
others demonstrating the same cause could be uncooperative and violating the law at a different gate.
Chapter 4 will discuss the key components of crowds involved in civil disturbances.
AFMAN31-201
17 MAY 2002
15
Chapter 4
THE PARTICIPANTS
4.1. The Environment. A civil disturbance occurs only in a particular environment--that environment is
a fusing of cause, place and willing confrontational participants. Civil disturbance participants come from
all backgrounds. Participants cover the broad spectrum from the far right to the far left. Participants may
be members of special interest groups, disgruntled or unemployed persons. They may be environmental-
ists, anti-nuclear agitators, anti-abortion activists or foreign and domestic opponents of US policy. They
come from all age groups and from all socioeconomic classes. Civil disturbance participants may be curi-
ous onlookers who have become swept away by the excitement of an event or demonstrators or counter
demonstrators who have become emotional about their cause. Whoever they are, they have become sub-
ject to the social and psychological factors that can turn a large gathering of people into a disruptive, dis-
orderly mob. Understanding these factors can help reduce disturbances and permit restoration of order
with a minimum of force.
4.2. The Human Factor. The basic human element sparking a disturbance is the presence of a crowd.
There are almost as many types of crowds as there are reasons for people to assemble. There are casual
crowds like those that assembles for a football game or gathers at an accident. Persons in such a crowd
probably have no common bonds other than the enjoyment of the game or curiosity about the accident.
There are “planned” crowds like those that assembles at the call of a leader to accomplish a goal. Mem-
bers of a planned crowd have common bonds of interest and purpose.
4.3. Impact of Social Factors on a Crowd. The presence or absence of social factors like leadership,
moral beliefs and social uniformity affect crowd behavior. Psychological factors also impact crowd
behaviors. Typically a crowd only does those things that the majority of its members want to do. How-
ever, the emotional stimulus and protection of being in a crowd (anonymity) can lead to a violent synergy
that individuals typically avoid. This dynamic, coupled with the fact that a crowd is open to manipulation,
is what makes a crowd particularly volatile and a threat to public order.
4.3.1. Leadership. Crowd situations are ripe with confusion and uncertainty. Members seek direction.
The first person to give orders in an authoritative manner is likely to be followed. A skillful manipu-
lator can channel the energy of a crowd toward violence or calmness. In riot situations, target the
group leadership at the early stages for apprehension. Leaderless crowds are much easier to disperse.
4.3.2. Emotional Contagion. Emotional contagion, a high state of excitement, provides the crowd
psychological unity. Although temporary, this unity or contagion may be the only momentum a crowd
needs to turn to mob action. Mob behavior is highly emotional, often unreasonable and always poten-
tially violent.
4.3.3. Panic. Panic prompts unreasoning and frantic efforts in seeking safety. It is extremely conta-
gious, spreads rapidly and endangers everyone in the area of the panicked crowd. Common panic sce-
narios include perceptions like:
4.3.3.1. Danger is so close at hand that the only action is to flee.
4.3.3.2. Escape routes are limited, blocked or have just been opened. Very often this form of panic
causes people to stampede. The onslaught of a fleeing human mass may result in people being
crushed, smothered or trampled.
16
AFMAN31-201 17 MAY 2002
4.3.3.3. Riot control agents have been used, crowd members cannot disperse quickly and there-
fore believe their lives are at risk.
4.3.4. These scenarios point to a critical concept in crowd control operations: Unless the mission is to
contain and capture, always provide a number of open, easily identifiable escape routes that a crowd
may access at any time.
4.4. Control Force Social Factors.
4.4.1. It is critical to remember that control force members are also susceptible to crowd behav-
iors--particularly panic. Do not allow control force members to develop a feeling of anonymity. Help-
ful measures include:
4.4.1.1. Leadership elements must know their people’s names and use them at every opportunity.
4.4.1.2. Personnel with questionable emotional stability or strong prejudices (particularly against
the crowd being controlled) should not participate in operations.
4.4.1.3. Do not dehumanize or depersonalize the crowd. It is easier to harm or fight an idea than a
person. Fair and impartial performance of control force duties is imperative.
4.4.1.4. Maintain a gender, ethnic and racial balance to offset the perception of a disturbance
being an “us” versus “them” situation. Mob leaders often count on sympathy generated from the
appearance of an overwhelming military force “attacking” old people, women and children.
4.4.2. Rigorous training, effective supervision and immediate corrective action of control force mem-
bers are an absolute requirement during civil disturbance operations. The fundamental fact is all mem-
bers of a control force are accountable for all of their actions.
4.5. Crowd Tactics. In civil disturbance situations, crowd tactics run the full spectrum. Typically, the
more organized a demonstration is, the more likely personnel will confront well-planned tactics. Keep in
mind, the underlying purpose for most tactics is to make the authorities, including the control force, look
bad. The perception of a heavy-handed response may add support to the protest, escalate demonstrator
acts (more violence) or serve to justify (in the minds of the crowd) outright acts of terrorism. This is why
each and every member of the control force must maintain a calm, professional demeanor--regardless of
the tactics.
4.5.1. Nonviolent Tactics.
4.5.1.1. Nonviolent tactics may range from name-calling to building barricades. Demonstrators
may converse with the control force members to distract, dissuade or gain their sympathy. Do not
respond to verbal barrages. “Civil disobedience” is the most common nonviolent tactic. Examples
include:
4.5.1.1.1. Trespassing--requiring control force apprehensions. Dissidents often view being
apprehended as a “victory” and stage tactics to force mass apprehensions in an attempt to sat-
urate the support functions behind control force units.
4.5.1.1.2. Passive resistance--blocking entrances, driveways, and offices--and then going
limp, thus requiring control force members to carry protesters away.
4.5.1.1.3. Chaining, handcuffing or tying themselves together and/or to an object associated
with the authorities (e.g., an aircraft, door, fence, or building).
AFMAN31-201
17 MAY 2002
17
4.5.1.2. Sometimes women, children and the elderly are placed in the front ranks. Consider this
real-world example: Mob planners prearranged media coverage. Their plan was to use only female
demonstrators in acts of civil disobedience. An astute installation commander who deployed only
female security forces and augmentees in blues, with no weapons or utility belts thwarted their
campaign. The security forces women effectively worked in pairs to carry away the passive
female demonstrators who had staged a sit-in across the main gate thoroughfare. The image of
Battle Dress Uniform-riot-clad security forces males removing these protesters never material-
ized. Result: The media blitz turned against the protesters--commending the restraint and profes-
sionalism displayed by the United States Air Force! Again, adapt a firm but impartial demeanor
when and if personnel must apprehend protesters.
4.5.1.3. Another common tactic (mentioned above) is to attempt to overwhelm the system by
staging groups for mass apprehensions. Consider how best to process violators:
4.5.1.3.1. In mass, all receive the same process.
4.5.1.3.2. Selectively--process and turn over to civil authorities the leaders, agitators and
repeat offenders while all others receive a debarment/expulsion letter.
4.5.1.3.3. Hold, identify and turn over to civil authorities.
4.5.1.3.4. The processing procedures will vary depending on each situation. Preplanning for
this phase of the contingency among civil authorities, the installation commander, judge advo-
cate and security forces is critical.
4.5.2. Violent Tactics.
4.5.2.1. A violent mob is potentially one of the most dangerous threats security forces will ever
face. Violent mobs are notorious for firebombing, brick throwing and breaking into and entering
secured facilities. Here are some less known, but just as deadly, tactics and weapons:
4.5.2.1.1. Balloons filled with paint to use as “bombs” on aircraft, buildings or control force
members.
4.5.2.1.2. Bolt cutters to cut through fences.
4.5.2.1.3. Clubs disguised to look like protest signs.
4.5.2.1.4. Lead pipes wrapped in newspaper to use as clubs or be thrown as deadly missiles.
4.5.2.1.5. Firecrackers dipped in glue and covered with BBs or small nails to use as miniature
shrapnel grenades.
4.5.2.1.6. Plywood shields and motorcycle helmets to protect against riot batons.
4.5.2.1.7. Goggles to protect against smoke and gas.
4.5.2.1.8. Ropes, chains, and grappling hooks to pull down fences. Mattresses, furniture pads
or heavy blankets to lay on top of barbed wire during breaching (trespass) movements.
4.5.2.1.9. Firearms, explosives and vehicle assaults (using vehicles to crash a gate, etc.) are
the most extreme forms of crowd violence.
18
AFMAN31-201 17 MAY 2002
4.5.2.2. Control force members disrupt a mob’s desired activity which makes the control force the
mob’s most immediate target and threat. Controlled, measured responses will ultimately subdue
any crowd. Control force members who get out of hand will only fuel and potentially escalate vio-
lence.
AFMAN31-201
17 MAY 2002
19
Chapter 5
TRAINING AND INFORMATION
5.1. Civil Disturbance Training. Crowd control situations, particularly those with a potential for vio-
lence, are best handled by a combination of planning and training. It is too late to train once a crisis
begins. As discussed earlier, given the out-of-mission role, coupled with the specialization required for
civil disturbance operations, just-in-time (JIT) training may be the most effective and efficient course of
action, if time allows. Lessons learned from several civil disturbance operations praised this training
methodology. Solid training, both JIT and annual sustainment, remains the best avenue to prepare security
forces for any contingency. Accurate information is the basis for appropriate training.
5.1.1. Generic Unit Training. Critical to any security forces operation is fitness for duty consideration.
When preparing Unit Type Codes (UTCs), security forces commanders must accurately plan, organize
and equip personnel who will deploy—whether to the front gate or around the world. AFH 31-305,
Security Forces Deployment Planning, is the standard for preparing SF UTCs. Numerous after-action
reports from civil disturbance operations reflect that UTCs deployed without assigned personnel
because of numerous humanitarian reasons. Some personnel deployed in spite of humanitarian prob-
lems. Personnel lacked proper immunizations critical for overseas deployment. Communications
equipment was often inadequate, incompatible or incomplete. Some UTCs deployed with weapons
and too much ammunition; others deployed with none. With the creation of the Aerospace Expedition-
ary Forces concept, some of these problems should disappear. Two absolutes, regardless of the mis-
sion, are:
5.1.1.1. Appropriate selection and training for deployment teams are critical to proper mission
preparation.
5.1.1.2. Tailoring of the deployed UTCs logistics detail for the specific deployment to ensure the
proper equipment is taken to complete the mission. In the near future, capability kits will be com-
pleted and propositioned at various locations to assist with these types of deployments.
5.1.2. Domestic Civil Disturbance Training.
5.1.2.1. Selection of the control force should draw on the unit’s most stable personnel. Training
should always emphasize tactics designed to present a disciplined show of force. Design training
to examine the degrees of force to use and priority of each. Every control force member must real-
ize they are responsible for their actions while performing civil disturbance duties. Following the
guidelines that established in AFI 31-207 is critical to the outcome of any situation. Much of the
training conducted for security forces has direct application in the realm of civil disturbance oper-
ations. Continually teaching and evaluating these topics should provide positive benefits when,
and if, security forces employ troops in civil disturbance missions:
5.1.2.1.1. Arming and use of force.
5.1.2.1.2. Unarmed self-defense.
5.1.2.1.3. Use of riot control agents and munitions.
5.1.2.1.4. Human relations and stress management.
5.1.2.1.5. Dealing with panic.
20
AFMAN31-201 17 MAY 2002
5.1.2.1.6. Weapons retention for the M-9, M-16 and M-870.
5.1.2.2. Specialized civil disturbance topics ideal for JIT training include:
5.1.2.2.1. Civil disturbance mission orientation and intelligence briefing.
5.1.2.2.2. Crowd control tactics.
5.1.2.2.3. Formations and movements.
5.1.2.2.4. Use of the baton.
5.1.2.2.5.
(Rapid) Flexicuffing.
5.1.2.2.6. The military working dog (MWD) in a civil disturbance environment.
5.1.2.2.7. Transporting large numbers of apprehended personnel.
5.1.2.2.8. Processing large numbers of apprehended personnel. NOTE: the above list is not
all-inclusive; therefore, commanders must adapt training to the local environment.
5.1.3. Foreign Civil Disturbance Training. Clearly, an MOOTW, foreign civil disturbance mission
requires more specialized JIT training in addition to the above-listed topics. Often an in-place country
team will conduct this training. These missions require an especially stable, properly selected control
force. Experience shows tours beyond 120 days induce considerable stress--even for the best pre-
pared. Third world nations rife with poverty, disease and different customs add to an already stressful
environment. Again, training should always emphasize a disciplined show of force, subject to the gov-
ernment, organization or individual in charge (e.g., UN, US State Department, US ambassador). Addi-
tional JIT training topics include:
5.1.3.1. Intelligence briefing.
5.1.3.2. Staff judge advocate briefing.
5.1.3.3. Cultural orientation--we need to overcome cultural barriers by learning about the nation/
culture we’re deployed to and make efforts to share our culture with them. Often, simple things are
overlooked. In some cultures, for example, people do not know about sanitary napkins, disposable
diapers or tying shoelaces--let alone how to use these items.
5.1.3.4. Morale strategies for US personnel and dissidents (particularly useful in migrant, intern-
ment and relocation camps).
5.1.3.5. Rumor control plan--for BOTH the control force and dissidents.
5.1.3.6. Control force escape, evasion, recovery and reconstitution plans--should mob violence
get out of hand or become life threatening to the control force.
5.2. Information Needs. Regardless of the deployment location, accurate and timely information is the
key to developing effective civil disturbance training plans. Process raw data into intelligence and feed it
up the chain of command. Analyze intelligence information and flow it back down the chain to those who
need it the most--control force members. The information focus must assess the social, economic and
political climate of the area and determine the likelihood of active participation or support from the local
populace. Federal law has strict limitations on the armed forces collecting, storing or disseminating per-
sonal data on US citizens. The control force commander should coordinate with civil and military attor-
neys throughout any operation involving US citizens.
AFMAN31-201
17 MAY 2002
21
5.3. Threat Analysis. Threat information is constantly changing. It is the most vital information force
planners when determining appropriate countermeasures, while guarding against overreaction. Establish
procedures for gathering, analyzing and disseminating this information in a timely fashion, both up and
down the chain of command. Three kinds of information produce a threat analysis:
5.3.1. Intelligence and criminal. Provide information on the goals, methods of operation, techniques,
strategies, tactics and targets of individuals or groups.
5.3.2. Threat. This information identifies and defines individuals and groups.
5.3.3. Vulnerability. Focuses on security weaknesses and high-risk targets (e.g., military installations,
utility plants, dams or dike works). To assess the vulnerability of the installation, consider:
5.3.3.1. Installation and surrounding community characteristics that would make an attractive tar-
get for terrorists or civil disturbance (e.g., nuclear mission, research and development facilities,
antiterrorism units, unique training missions).
5.3.3.2. Status of training. Readiness can be a powerful deterrent.
5.3.3.3. Communications availability/vulnerability.
5.3.3.4. Nonmilitary law enforcement resources.
5.3.3.5. Time and distance from other US military installations that could provide support.
5.3.3.6. Time and distance from urban areas. Large urban areas offer choice targets; ease of infil-
tration, concealment and escape; and large concentrations of ethnic populations that may be sym-
pathetic to a particular cause.
5.3.3.7. Geographic region and proximity to foreign borders.
5.3.3.8. Access to the installation or community--power grids, fuel depots and pipelines.
5.3.3.9. Population density of the installation or community.
5.3.3.10. Terrain.
5.3.3.11. Weather.
22
AFMAN31-201 17 MAY 2002
Chapter 6
OPERATIONS
6.1. Restore Order. Security forces must isolate any civil disturbance threatening military order and pre-
vent the disturbance from spreading. Security forces protect people, facilities and services. Mob demon-
strators usually view control force members as defenders of the “status quo” and thereby consider them
targets. Above all, the control force mission is to provide disciplined restraint to maintain law and order.
The nature of control force operations can vary greatly. Adopt operational strategies from AFH 31-305.
Use this manual to prepare specific mission plans.
6.2. Isolate the Disturbance.
6.2.1. The initial control task is to isolate the crowd and seal off the disturbance area. Once isolated,
time becomes the commander’s ally. To achieve this end, initiate measures to:
6.2.1.1. Prevent disorder from spreading to unaffected areas.
6.2.1.2. Move uninvolved people from the area immediately.
6.2.1.3. Prevent unauthorized people from entering the disturbance area.
6.2.1.4. Apprehend disturbance leaders/agitators.
6.2.2. Once the four control measures above are in place, allow the crowd to disperse peacefully. Iso-
late the affected area much the same as we do restricted areas: use signs, barriers and mobile patrols.
Apprehend individuals in the mob who refuse to leave immediately and remove them from the area so
they cannot reorganize or rekindle the crowd into an unruly mob.
6.3. Protect Targets. In most civil disturbance missions, security forces will be assigned to protect “tar-
gets” from the crowd. Targets include people and facilities. Adapt procedures from AFI 31-101, The Air
Force Installation Security Program and C-5210-41M, Nuclear Weapon Security Manual/Air Force Sup-
plement, to fulfill this aspect of the mission. Table 6.1. provides a simplified overview.
6.4. Crowd Control.
6.4.1. The control force uses carefully selected tactics and wisely committed resources to exert con-
trol over disorderly crowds. Installation/operation commanders have four basic options available to
them. Their order can be to monitor, disperse, contain or block the crowd. Implement these options
alone or in combination. Variables that might influence the tactic(s) applied include:
6.4.1.1. Severity of the disturbance.
6.4.1.2. Public opinion.
6.4.1.3. Current policies.
6.4.1.4. Crowd demographics (mood, intent, composition and activity).
6.4.1.5. Capabilities and preparedness of control forces.
6.4.1.6. Immediate and long-term benefits of control force action.
6.4.1.7. Weather, terrain and time of day.
AFMAN31-201
17 MAY 2002
23
Table 6.1. Civil Disturbance Target Security Measures
LIKELY TARGETS
COUNTERMEASURES
Restrict personal data releases.
Do not provide/identify VIP parking, office or residence
locations.
Work with key personnel to maintain a low profile.
Conduct counter surveillance and keep VIPs fully informed.
VIPs
Establish duress codes and appropriate response procedures
for all valid threats.
Limit information on VIP travel routes, meetings, times,
locations and all itineraries to as few people as possible.
Consider protective services.
Deploy 4-person teams, at a minimum, during mob violence.
NEVER allow control force members to patrol alone.
Prohibit off-duty control force members from the disturbance
CONTROL
area.
FORCE
Never locate the control force garrison within sight or sound
of a disturbance area.
Establish escape, evasion, recovery and reconstitution plans
in the event of mob ambush/breakout.
FACILITIES
Prevent direct access--establish personnel recognition
systems, badges, sign-counter sign, etc.
Equip sensitive areas (reception rooms, entrances, control
centers) with duress alarms.
Escort visitors into and out of sensitive areas.
Secure entrances to sensitive areas. Lock, post or patrol as
appropriate.
Establish a “safe room” within facilities should a mob breach
the outer defenses.
Store and secure supplies vital for extended operations.
6.4.2. Monitor.
6.4.2.1. Monitoring does not antagonize peaceful gatherings and is appropriate when more deci-
sive action is inappropriate. Monitoring is particularly useful in large, non-violent demonstrations.
This is also an ideal stage to meet demonstration leaders, determine their intent and gain their
cooperation. Contact with the leadership may be the only control measure needed, persuading
leaders to police (literally) their own gathering. Planned demonstrations usually require coordina-
tion of the following options:
6.4.2.1.1. Formal issuance of permits to march or demonstrate.
6.4.2.1.2. Planned starting point, route and rally point(s) for the demonstration.
6.4.2.1.3. Time schedule.
6.4.2.1.4. The need to marshal/escort the demonstration and which organization will provide
personnel to serve as marshals.
24
AFMAN31-201 17 MAY 2002
6.4.2.1.5. Violence, litter and property damage prevention.
6.4.2.1.6. Personnel safety.
6.4.2.2. Assigning a member of the control force to photograph faces of crowd members is an
extremely effective part of monitoring. When individuals in crowds realize they are being photo-
graphed, security forces neutralize the anonymity that adds to their brazenness. Crowd members
need to see the photographer. The photographer needs to be in uniform. There should be no doubt
in anyone’s mind that individuals in the crowd are being photographed (still or video) by the con-
trol force. Ensure the safety of the photographer. Should the mob turn violent, photographic evi-
dence can be remarkably beneficial.
6.4.3. Disperse.
6.4.3.1. The control force may disperse the crowd. Key to any dispersal operation is control and
orderliness. An uncontrolled, fragmented crowd may actually spread violence and damage.
Clearly inform the crowd of the requirement to disperse. Detail authorized egress routes. Maintain
(likely) target countermeasures. Apprehend any small groups that resist or loiter in the area after
dispersal. A hierarchy of dispersal options includes:
6.4.3.1.1. Violent, destructive confrontations. Format: Top (first resort) to bottom (last resort):
6.4.3.1.1.1. Monitor, release/read a proclamation “this may display a show of force.”
6.4.3.1.1.2. Increase four-person and MWD patrols.
6.4.3.1.1.3. Employ crowd control formations.
6.4.3.1.1.4. Implement riot tactics.
6.4.3.1.1.5. Employ water cannon.
6.4.3.1.1.6. Employ chemical agents.
6.4.3.1.1.7. Employ lethal force.
6.4.3.2. Peaceful demonstrations. Adapt this hierarchy to specific situations.
6.4.4. Contain. Containment is a suitable option for keeping disorder from spreading and when the
commander directs apprehensions. Vehicles, which are under the control of the on-scene commander,
may be an excellent force multiplier. Used jointly with dismounted troops, the 33-ton crash (fire)
trucks are a ready resource (known to be resoundingly successful) and have a tremendous psycholog-
ical impact on mobs. Lights, sirens and public address systems on law enforcement vehicles--used
judiciously--can aid containment efforts. When using vehicles in a containment operation, establish
an actual, mobile command post.
6.4.5. Block. Blocking may be necessary to protect specific targets in the path of an advancing crowd
(e.g., keeping an unruly mob off the flight line to protect aircraft). Control force members on line or in
vehicles are common barricades. Depending on the severity of the violence or threat, erect concertina
wire, earthen-filled barrels or jersey barriers to counter higher level threats like speeding vehicles or
mass breaches.
6.5. Establishing (Civil) Control. On Air Force installations, security forces serve as an extension of the
commander’s military authority to protect life and property. The legal lines of authority are clear and dis-
tinct. However, in off-base disturbances, the role of the military is to support, not supplant, civil authority.
|
||
|
|
|